VYPR
Medium severity5.0NVD Advisory· Published Oct 9, 2019· Updated Jun 17, 2026

CVE-2019-3652

CVE-2019-3652

Description

Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.

Affected products

4
  • McAfee, LLC/McAfee Endpoint Security (ENS)v5
    Range: 10.6.x
  • McAfee/Endpoint Securityllm-fuzzy3 versions
    < 10.6.1 October 2019 Update+ 2 more
    • (no CPE)range: < 10.6.1 October 2019 Update
    • cpe:2.3:a:mcafee:endpoint_security:*:*:*:*:*:*:*:*range: >=10.5.0,<=10.5.5
    • cpe:2.3:a:mcafee:endpoint_security:10.6.1:-:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.