VYPR
Medium severity5.0NVD Advisory· Published Sep 4, 2020· Updated Jun 17, 2026

CVE-2020-7299

CVE-2020-7299

Description

Cleartext Storage of Sensitive Information in Memory vulnerability in Microsoft Windows client in McAfee True Key (TK) prior to 6.2.109.2 allows a local user logged in with administrative privileges to access to another user’s passwords on the same machine via triggering a process dump in specific situations.

Affected products

3
  • McAfee/True Key2 versions
    cpe:2.3:a:mcafee:true_key:*:*:*:*:*:windows:*:*+ 1 more
    • cpe:2.3:a:mcafee:true_key:*:*:*:*:*:windows:*:*range: <6.2.109.2
    • (no CPE)range: <6.2.109.2
  • McAfee,LLC/McAfee True Key Windows clientv5
    Range: 6.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.