Show filters
7 Total Results
Displaying 1-7 of 7
Sort by:
Attacker Value
Unknown
CVE-2023-5607
Disclosure Date: November 27, 2023 (last updated December 02, 2023)
An improper limitation of a path name to a restricted directory (path traversal) vulnerability in the TACC ePO extension, for on-premises ePO servers, prior to version 8.4.0 could lead to an authorised administrator attacker executing arbitrary code through uploading a specially crafted GTI reputation file. The attacker would need the appropriate privileges to access the relevant section of the User Interface. The import logic has been updated to restrict file types and content.
0
Attacker Value
Unknown
CVE-2023-0221
Disclosure Date: January 13, 2023 (last updated November 08, 2023)
Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.
0
Attacker Value
Unknown
CVE-2021-31833
Disclosure Date: January 04, 2022 (last updated October 07, 2023)
Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would usually be prevented by MACC. This would require the attacker to rename the specified binary to match name of any configured updater and perform a specific set of steps, resulting in the renamed binary to be to run.
0
Attacker Value
Unknown
CVE-2020-7334
Disclosure Date: October 15, 2020 (last updated February 22, 2025)
Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This version adds further controls for installation/uninstallation of software.
0
Attacker Value
Unknown
CVE-2020-7309
Disclosure Date: August 26, 2020 (last updated February 22, 2025)
Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.
0
Attacker Value
Unknown
CVE-2020-7260
Disclosure Date: March 24, 2020 (last updated February 21, 2025)
DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.
0
Attacker Value
Unknown
McAfee Application Control and Change Control (MACC) - password management secu…
Disclosure Date: September 18, 2018 (last updated November 08, 2023)
Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.
0