CVE-2020-7337
Estado: ModificadaMedia (6.7)—
Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.41%
- Percentil entre todas las CVEs puntuadas: 33
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-732
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2020-7337",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.6,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "trellixpsirt@trellix.com",
"affectedData": [
{
"vendor": "McAfee, LLC",
"product": "VirusScan Enterprise (VSE)",
"versions": [
{
"status": "affected",
"version": "8.8.x",
"versionType": "custom",
"lessThanOrEqual": "patch 15"
}
]
}
]
}
],
"published": "2020-12-09T09:15:13.200",
"references": [
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10338",
"source": "trellixpsirt@trellix.com"
},
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10338",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks."
},
{
"lang": "es",
"value": "Una vulnerabilidad de Asignación de Permisos Incorrecta de Recursos Críticos en McAfee VirusScan Enterprise (VSE) versiones anteriores a 8.8 Parche 16 permite a administradores locales omitir la protección de seguridad local por medio de VSE que no se integra correctamente con Windows Defender Application Control mediante la manipulación cuidadosa de las comprobaciones de Integridad del Código"
}
],
"lastModified": "2026-06-17T03:24:44.510",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "324B63C7-6AA0-4943-935E-85A1F949C509",
"versionEndExcluding": "8.8"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "739CE02A-E38F-4B8E-8902-FB6C6DF0C2D6"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D14CEFB-F8A2-4E07-8248-C8DDE8665EB0"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CA1D6C3D-0496-43DB-85EF-0F9801F8DD54"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "586B2C78-640C-475F-9ED3-ECDA83F8B26A"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE55ECB6-2B28-4A1A-A8BA-17ADFB97D61A"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9C79BC0A-E955-4170-AE0C-E6868FF38E92"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E87B844-7FE9-4AB6-8E09-B22A9419079A"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2F27699-3594-4B59-891E-0241AE13D7E4"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D5550350-5035-41AB-BCD0-D24E669839C1"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E7DF43DB-F296-4D0E-89F0-B807DBC750C0"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4095418F-39EF-4A47-BCBA-BEE0B81B4E51"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "441512BE-F8A5-4690-9005-DCAB0EE86CC3"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "04273536-A593-4439-9325-1C57BAAB60D8"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC9F3CB2-5A92-4EBB-B109-44690EE096FF"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5AE7C3D5-9771-40A9-B7A3-37EFEFC9FD9E"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61ADDBB0-F71D-46D1-9DB5-38905954C33A"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "trellixpsirt@trellix.com"
}