ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-7346

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) for Windows prior to 11.6.100 allows a local, low privileged, attacker through the use of junctions to cause the product to load DLLs of the attacker's choosing. This requires the creation and removal of junctions by the attacker along with sending a specific IOTL command at the correct time.
7.8
CVSS
6.4
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityLow
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusUnavailable

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P4.4 → 6.4
2026-07-21cve.orginitial, patch: Unavailable4.4

Affected Software
VendorProductVersion
mcafeedata_loss_prevention< 11.6.100
McAfee,LLCMcAfee Data Loss Prevention (DLP) Endpoint for Windows< 11.6.100
Published: 2021-03-23