VYPR

Application And Change Control

by McAfee

CVEs (8)

  • CVE-2020-7334HigOct 15, 2020
    risk 0.50cvss 7.7epss 0.00

    Improper privilege assignment vulnerability in the installer McAfee Application and Change Control (MACC) prior to 8.3.2 allows local administrators to change or update the configuration settings via a carefully constructed MSI configured to mimic the genuine installer. This…

  • CVE-2020-7260HigMar 26, 2020
    risk 0.47cvss 7.3epss 0.00

    DLL Side Loading vulnerability in the installer for McAfee Application and Change Control (MACC) prior to 8.3 allows local users to execute arbitrary code via execution from a compromised folder.

  • CVE-2021-31833HigJan 4, 2022
    risk 0.46cvss 7.1epss 0.00

    Potential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally logged in attacker to circumvent the application solidification protection provided by MACC, permitting them to run applications that would…

  • CVE-2018-6690HigSep 18, 2018
    risk 0.46cvss 7.1epss 0.00

    Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

  • CVE-2018-6669MedDec 20, 2018
    risk 0.41cvss 6.3epss 0.01

    A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.

  • CVE-2023-0221MedJan 13, 2023
    risk 0.29cvss 4.4epss 0.00

    Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program.

  • CVE-2017-3912MedSep 18, 2018
    risk 0.29cvss 4.4epss 0.00

    Bypassing password security vulnerability in McAfee Application and Change Control (MACC) 7.0.1 and 6.2.0 allows authenticated users to perform arbitrary command execution via a command-line utility.

  • CVE-2020-7309LowAug 26, 2020
    risk 0.25cvss 3.9epss 0.00

    Cross Site Scripting vulnerability in ePO extension in McAfee Application Control (MAC) prior to 8.3.1 allows administrators to inject arbitrary web script or HTML via specially crafted input in the policy discovery section.