VYPR
Medium severity6.5NVD Advisory· Published Dec 9, 2020· Updated Jun 17, 2026

CVE-2020-7337

CVE-2020-7337

Description

Incorrect Permission Assignment for Critical Resource vulnerability in McAfee VirusScan Enterprise (VSE) prior to 8.8 Patch 16 allows local administrators to bypass local security protection through VSE not correctly integrating with Windows Defender Application Control via careful manipulation of the Code Integrity checks.

Affected products

19
  • cpe:2.3:a:mcafee:virusscan_enterprise:*:*:*:*:*:*:*:*+ 17 more
    • cpe:2.3:a:mcafee:virusscan_enterprise:*:*:*:*:*:*:*:*range: <8.8
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:-:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch10:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch11:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch12:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch13:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch14:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch15:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch1:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch2:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch3:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch4:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch5:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch6:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch7:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch8:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch9:*:*:*:*:*:*
    • (no CPE)range: < 8.8 Patch 16
  • McAfee, LLC/VirusScan Enterprise (VSE)v5
    Range: 8.8.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.