ZeroHour

CVE-2021-23892

CVSS 3.1
7.0 high
EPSS
<1%p9
Published
()
Modified
Description

By exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (ENSL TP/FW) installation process, a local user can perform a privilege escalation attack to obtain administrator privileges for the purpose of executing arbitrary code through insecure use of predictable temporary file locations.

Vendors
mcafee
Products
endpoint security for linux threat prevention
Weakness
CWE-59, CWE-367
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.