Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

McAfee Endpoint Security (ENS) — Vulnerabilities & Security Advisories 17

All 17 CVE vulnerabilities found in McAfee Endpoint Security (ENS), with AI-generated Chinese analysis, references, and POCs.

This page aggregates known vulnerabilities associated with McAfee Endpoint Security (ENS), categorized by weakness type and tracked under the Vendor Product Tag system. It compiles security findings reported across multiple databases, focusing on flaws that impact endpoint protection mechanisms such as intrusion prevention, anti-malware, and firewall modules. The collection covers vulnerabilities discovered between January 2010 and the present, providing a comprehensive historical view of security issues affecting this specific enterprise security solution. Readers can use this resource to track vendor advisories from McAfee and related entities, gaining insight into how specific weaknesses have been addressed over time. The page also helps users understand the broader context of a particular weakness class within the endpoint security landscape, illustrating how similar vulnerabilities manifest in different components of the product suite. Additionally, users can look up the product's vulnerability history to assess the long-term security posture of the software, identifying trends in reporting and remediation speed. This structured approach allows security professionals to evaluate the risk profile of their deployment environments more effectively. By centralizing these data points, the page serves as a reference for researchers and IT administrators who need to correlate specific weaknesses with their corresponding product versions and update patches. It does not offer technical mitigation steps but rather provides the essential metadata needed to inform patch management strategies and risk assessments.

Vendor: McAfee, LLC

CVE IDTitleCVSSSeverityPublished
CVE-2020-7331 Unquoted service executable path in McAfee Endpoint Security (ENS) CWE-428 7.8 High2020-11-12
CVE-2020-7255 Privilege Escalation vulnerability  in ENS CWE-264 3.9 Low2020-04-15
CVE-2020-7250 ENS symbolic link log file manipulation vulnerability CWE-59 8.2 High2020-04-15
CVE-2020-7257 Privilege Escalation vulnerability through Symbolic links in ENS CWE-264 8.4 High2020-04-15
CVE-2020-7259 Unsigned executable vulnerability in ENS can be used to bypass intended self-protection rules CWE-264 6.6 Medium2020-04-15
CVE-2020-7261 Buffer overwrite in ENS allowed to bypass AMSI protection CWE-119 6.1 Medium2020-04-15
CVE-2020-7273 Autorun registry bypass CWE-269 6.7 Medium2020-04-15
CVE-2020-7275 Unquoted service paths for some McAfee ENS files CWE-428 4.8 Medium2020-04-15
CVE-2020-7274 ENS elevated permissions vulnerability CWE-269 6.6 Medium2020-04-15
CVE-2020-7277 McAfee processes not protected CWE-693 6.8 Medium2020-04-15
CVE-2020-7276 Unrestricted Policy Management using MfeUpgradeTool.exe CWE-287 6.4 Medium2020-04-15
CVE-2020-7278 McAfee firewall rules not enforced correctly CWE-284 7.4 High2020-04-15
CVE-2020-7251 ESConfig Tool able to edit configuration for newer version CWE-358 5.0 Medium2020-02-14
CVE-2019-3653 ESConfig Tool access not controlled CWE-284 4.6 Medium2019-10-09
CVE-2019-3652 ENS code injection in EPSetup.exe CWE-94 5.0 Medium2019-10-09
CVE-2019-3586 McAfee Endpoint Security firewall not always acting on GTI lookup results CWE-693 4.7 -2019-05-15
CVE-2019-3582 McAfee Endpoint Security updates fix a privilege escalation vulnerability 7.8 -2019-02-28

All 17 known CVE vulnerabilities affecting McAfee Endpoint Security (ENS) with full Chinese analysis, references, and POCs where available.