Endpoint Security

Vendor:

First CVE: Apr 8, 2016 · Active for 10 years

37
Total CVEs
More Total CVEs than 97% of tracked products
6.2
Avg CVEs / Year
Higher CVE frequency than 91% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Endpoint Security over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 8, 2016
10 years ago
Most Recent CVE
Sep 17, 2021
1,771 days ago

CVE Severity & Scoring

Endpoint Security37 CVEs
All CVEs352,294 CVEs
MediumHigh
Attack Vector
Local30 (81.1%)
Network6 (16.2%)
Unknown0 (0.0%)
Physical1 (2.7%)
Adjacent Network0 (0.0%)
Attack Complexity
Low33 (89.2%)
High4 (10.8%)
Unknown0 (0.0%)
User Interaction
None30 (81.1%)
Unknown0 (0.0%)
Required7 (18.9%)
Privileges Required
Low22 (59.5%)
High11 (29.7%)
None4 (10.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (37 CVEs).

37 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL)
Apr 8, 20165.127NOYES
Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrar
Nov 12, 20208.826NONO
Improper Access Control vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local users to access files which the user otherwis
Sep 9, 20208.826NONO
Privilege Escalation vulnerability in Microsoft Windows client in McAfee Endpoint Security (ENS) 10.6.1 and earlier allows local users to gain elevated privileges via a specific se
Feb 28, 20197.826NONO
Improper privileges management vulnerability in McAfee Endpoint Security (ENS) Windows prior to 10.7.0 September 2021 Update allows local users to access files which they would oth
Sep 17, 20217.825NONO
Application protections bypass vulnerability in Intel Security McAfee Application Control (MAC) 7.0 and earlier and Endpoint Security (ENS) 10.2 and earlier allows local users to b
Mar 14, 20177.825NONO
Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution
Nov 12, 20207.824NONO
Symbolic link manipulation vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2020 Update allows authenticated local user to potentially gain an e
Apr 15, 20207.824NONO
Protection Mechanism Failure in the Firewall in McAfee Endpoint Security (ENS) 10.x prior to 10.6.1 May 2019 update allows context-dependent attackers to circumvent ENS protection
May 15, 20197.523NONO
Protection Mechanism Failure vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2020 Update allows local administrator to temporarily reduce the
Sep 9, 20207.322NONO

Exploit Exposure

Signals from CVEs in this product scope (37 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
2.7% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (37 CVEs).

Media Mentions

Signals from CVEs in this product scope (37 CVEs).

Top CNAs Publishing CVEs For Endpoint Security

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
10.7.056.80.3%00
10.6.146.50.5%00
10.6.0136.50.3%00
10.5.5126.30.3%00
10.5.4126.30.3%00
10.5.3126.30.3%00
10.5.2126.30.3%00
10.5.1126.30.3%00
10.5.0126.30.3%00
10.214.40.5%00
10.16.115.50.2%00