Authentication bypass vulnerability in MfeUpgradeTool in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 April 2020 Update allows administrator users to access policy settings via running this tool.
| Software | From | Fixed in |
|---|---|---|
| mcafee / endpoint_security | 10.5.0 | 10.5.0.x |
| mcafee / endpoint_security | 10.5.1 | 10.5.1.x |
| mcafee / endpoint_security | 10.5.2 | 10.5.2.x |
| mcafee / endpoint_security | 10.5.3 | 10.5.3.x |
| mcafee / endpoint_security | 10.5.4 | 10.5.4.x |
| mcafee / endpoint_security | 10.5.5 | 10.5.5.x |
| mcafee / endpoint_security | 10.6.0 | 10.6.0.x |