
Cloud Vulnerability DB
A community-led vulnerabilities database
A Null Pointer Dereference vulnerability (CVE-2021-23883) was discovered in McAfee Endpoint Security (ENS) for Windows prior to version 10.7.0 February 2021 Update. The vulnerability allows a local administrator to cause Windows to crash via a specific system call which is not handled correctly. The severity of this issue varies by machine and had partial protection prior to this update (NVD, CVE).
The vulnerability is classified as a Null Pointer Dereference (CWE-476) issue. The vulnerability occurs when a specific system call is not handled correctly by the McAfee Endpoint Security software, leading to a potential system crash (NVD CNA Status).
When exploited, this vulnerability can cause Windows to crash, resulting in a denial of service condition. The impact varies depending on the specific machine configuration (CVE).
The vulnerability requires local administrator access to exploit, which somewhat limits its potential impact. The exploit involves making a specific system call that triggers the null pointer dereference (NVD).
The vulnerability was addressed in McAfee Endpoint Security (ENS) for Windows version 10.7.0 February 2021 Update. Users should upgrade to this version or later to mitigate the vulnerability (McAfee Security Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."