VendorsMcAfeeendpoint_securityall versions
Vulnerabilities

McAfee Endpoint Security

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2020-7332
Cross-Site Request Forgery (CSRF) in firewall ePO extension of McAfee Endpoint Security (ENS)
Published 2020-11-12 · Modified
8.8EPSS 0.006
CVE-2020-7319
Improper Access Control Vulnerability in ENS for Windows
Published 2020-09-09 · Modified
8.8EPSS 0.004
CVE-2020-7264
Privilege Escalation vulnerability through symbolic links in ENS for Windows
Published 2020-05-08 · Modified
8.8EPSS 0.003
CVE-2020-7265
Privilege Escalation vulnerability through symbolic links in ENSM
Published 2020-05-08 · Modified
8.8EPSS 0.003
CVE-2019-3582
McAfee Endpoint Security updates fix a privilege escalation vulnerability
Published 2019-02-28 · Modified
8.6EPSS 0.004
CVE-2020-7257
Privilege Escalation vulnerability through Symbolic links in ENS
Published 2020-04-15 · Modified
8.4EPSS 0.003
CVE-2020-7250
ENS symbolic link log file manipulation vulnerability
Published 2020-04-15 · Modified
8.2EPSS 0.004
CVE-2021-23882
Improper Access Control in the ENS installer
Published 2021-02-10 · Modified
8.2EPSS 0.003
CVE-2020-7331
Unquoted service executable path in McAfee Endpoint Security (ENS)
Published 2020-11-12 · Modified
7.8EPSS 0.004
CVE-2021-31843
Improper access control vulnerability in McAfee ENS for Windows
Published 2021-09-17 · Modified
7.8EPSS 0.003
CVE-2016-8010
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to bypass local security protection via a command-line utility.
Published 2017-03-14 · Modified
7.8EPSS 0.003
CVE-2020-7259
Unsigned executable vulnerability in ENS can be used to bypass intended self-protection rules
Published 2020-04-15 · Modified
7.8EPSS 0.003
CVE-2020-7274
ENS elevated permissions vulnerability
Published 2020-04-15 · Modified
7.8EPSS 0.002
CVE-2019-3586
McAfee Endpoint Security firewall not always acting on GTI lookup results
Published 2019-05-15 · Modified
7.5EPSS 0.008
CVE-2020-7278
McAfee firewall rules not enforced correctly
Published 2020-04-15 · Modified
7.4EPSS 0.006
CVE-2021-23878
Clear text storage of sensitive Information in ENS
Published 2021-02-10 · Modified
7.3EPSS 0.006
CVE-2020-7320
Protection Mechanism Failure in ENS for Windows
Published 2020-09-09 · Modified
7.3EPSS 0.003
CVE-2020-7323
Authentication Protection Bypass vulnerability in ENS for Windows
Published 2020-09-09 · Modified
6.9EPSS 0.003
CVE-2020-7277
McAfee processes not protected
Published 2020-04-15 · Modified
6.8EPSS 0.003
CVE-2021-23880
Improper Access Control in the ENS installer
Published 2021-02-10 · Modified
6.7EPSS 0.003
CVE-2020-7276
Unrestricted Policy Management using MfeUpgradeTool.exe
Published 2020-04-15 · Modified
6.7EPSS 0.003
CVE-2020-7273
Autorun registry bypass
Published 2020-04-15 · Modified
6.7EPSS 0.002
CVE-2020-7263
ENS configuration can be edited by attacker with local administrator permissions
Published 2020-04-01 · Modified
6.7EPSS 0.002
CVE-2020-7308
Transmission of data in clear text by McAfee ENS
Published 2021-04-15 · Modified
6.5EPSS 0.005
CVE-2020-7261
Buffer overwrite in ENS allowed to bypass AMSI protection
Published 2020-04-15 · Modified
6.1EPSS 0.003
CVE-2019-3653
ESConfig Tool access not controlled
Published 2019-10-09 · Modified
5.5EPSS 0.002
CVE-2021-31842
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.
Published 2021-09-17 · Modified
5.5EPSS 0.002
CVE-2020-7251
ESConfig Tool able to edit configuration for newer version
Published 2020-02-14 · Modified
5.5EPSS 0.002
CVE-2019-3652
ENS code injection in EPSetup.exe
Published 2019-10-09 · Modified
5.3EPSS 0.003
CVE-2020-7275
Unquoted service paths for some McAfee ENS files
Published 2020-04-15 · Modified
5.3EPSS 0.003
CVE-2016-3984
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
Published 2016-04-08 · Modified
5.11 PoCEPSS 0.011
CVE-2017-4028
SB10193 - consumer and corporate products - Maliciously misconfigured registry vulnerability
Published 2018-04-03 · Modified
5.0EPSS 0.005
CVE-2021-23883
Null Pointer Dereference vulnerability in McAfee Endpoint Security (ENS)
Published 2021-02-10 · Modified
4.9EPSS 0.003
CVE-2021-23881
Stored Cross Site Scripting in ENS
Published 2021-02-10 · Modified
4.8EPSS 0.006
CVE-2020-7333
Cross-site Scripting (XSS) in firewall ePO extension of McAfee Endpoint Security (ENS)
Published 2020-11-12 · Modified
4.8EPSS 0.005
CVE-2020-7322
Exposure of Sensitive Information in ENS for Windows
Published 2020-09-09 · Modified
4.7EPSS 0.002
CVE-2020-7255
Privilege Escalation vulnerability  in ENS
Published 2020-04-15 · Modified
4.4EPSS 0.002