{"id":238045,"date":"2020-11-25T16:57:17","date_gmt":"2020-11-25T15:57:17","guid":{"rendered":"https:\/\/www.borncity.com\/blog\/?p=238045"},"modified":"2023-03-22T08:50:00","modified_gmt":"2023-03-22T07:50:00","slug":"windows-schwachstellen-in-mcafee-endpoint-security-nov-2020","status":"publish","type":"post","link":"https:\/\/borncity.com\/blog\/2020\/11\/25\/windows-schwachstellen-in-mcafee-endpoint-security-nov-2020\/","title":{"rendered":"Windows: Schwachstellen in McAfee Endpoint Security (Nov. 2020)"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" style=\"float: left; margin: 0px 10px 0px 0px; display: inline;\" src=\"https:\/\/borncity.com\/blog\/wp-content\/uploads\/2015\/01\/Schutz.jpg\" width=\"40\" height=\"47\" align=\"left\" \/>[<a href=\"https:\/\/borncity.com\/win\/2020\/11\/25\/windows-schwachstellen-in-mcafee-endpoint-security-nov-2020\/\" target=\"_blank\" rel=\"noopener noreferrer\">English<\/a>]Nutzer die McAfee Endpoint Security einsetzen, sollten das Produkt updaten. Denn Schwachstellen gef\u00e4hrden die Sicherheit von Windows. Hier einige Informationen.<\/p>\n<p><!--more--><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vg07.met.vgwort.de\/na\/0011d58fe4214a45b32dc10de056a45a\" alt=\"\" width=\"1\" height=\"1\" \/>McAfee Endpoint Security ist eine <a href=\"https:\/\/web.archive.org\/web\/20201125145717\/https:\/\/www.mcafee.com\/enterprise\/de-de\/assets\/data-sheets\/ds-endpoint-security.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">Sicherheitsl\u00f6sung f\u00fcr Unternehmen<\/a>, die Endger\u00e4te sch\u00fctzen m\u00f6chten. Das Produkt bietet Machine Learning, zum Schutz vor dem Diebstahl von Anmeldeinformationen und Behebung durch Rollback zur Erg\u00e4nzung der grundlegenden Sicherheitsfunktionen von Windows Desktop- und Server-Systemen. In einem <a href=\"https:\/\/web.archive.org\/web\/20211206100350\/https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10335\" target=\"_blank\" rel=\"noopener noreferrer\">Sicherheitshinweis vom 10. November 2020 warnt McAfee<\/a> jetzt vor gleich drei Schwachstellen (CVE-2020-7331 , CVE-2020-7332 und CVE-2020-7333), die in \u00e4lteren Produktversionen enthalten sind und die Sicherheit von Windows gef\u00e4hrden.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20211206100350\/https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10335\" target=\"_blank\" rel=\"noopener noreferrer\"><img decoding=\"async\" title=\"Schwachstellen in McAfee Endpoint Security\" src=\"https:\/\/i.imgur.com\/0SfF0Lq.png\" alt=\"Schwachstellen in McAfee Endpoint Security\" \/><\/a><br \/>\n(Schwachstellen in McAfee Endpoint Security, Quelle: <a href=\"https:\/\/web.archive.org\/web\/20211206100350\/https:\/\/kc.mcafee.com\/corporate\/index?page=content&amp;id=SB10335\" target=\"_blank\" rel=\"noopener noreferrer\">McAfee<\/a>)<\/p>\n<ul>\n<li><strong>CVE-2020-7331: <\/strong>Unquoted service executable path in McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.<\/li>\n<li><strong>CVE-2020-7332: <\/strong>Cross Site Request Forgery vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows an attacker to execute arbitrary HTML code due to incorrect security configuration.<\/li>\n<li><strong>CVE-2020-7333_ <\/strong>Cross site scripting vulnerability in the firewall ePO extension of McAfee Endpoint Security (ENS) prior to 10.7.0 November 2020 Update allows administrators to inject arbitrary web script or HTML via the configuration wizard.<\/li>\n<\/ul>\n<p>Betroffen von diesen Schwachstellen sind:<\/p>\n<ul>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923033209\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Firewall&amp;v=10.7.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Firewall 10.7.x<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923033314\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Firewall&amp;v=10.6.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Firewall 10.6.x<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923034805\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Threat+Prevention&amp;v=10.7.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Threat Prevention 10.7.x<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923033715\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Threat+Prevention&amp;v=10.6.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Threat Prevention 10.6.x<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923033247\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Web+Control&amp;v=10.7.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Web Control 10.7.x<\/a><\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20210923033730\/https:\/\/support.mcafee.com\/webcenter\/portal\/supportportal\/pages_knowledgecenter?p=Endpoint+Security+Web+Control&amp;v=10.6.x&amp;lang=en_US&amp;facets=Security%20Bulletins%40INQUIRA_TYPE&amp;s=true&amp;sm=true&amp;tab=SCtdl&amp;sb=mostRelevant&amp;sbv=relevance\" target=\"_blank\" rel=\"noopener noreferrer\">Endpoint Security Web Control 10.6.x<\/a><\/li>\n<\/ul>\n<p>McAfee hat f\u00fcr die betreffenden Produkte Updates zum Schlie\u00dfen dieser Schwachstellen herausgegeben.<\/p>\n<ul>\n<li>ENS for Windows 10.7.0<\/li>\n<li>ENS for Windows 10.6.1<\/li>\n<\/ul>\n<p>Weitere Details sind der McAfee Sicherheitsmeldung zu entnehmen (<a href=\"https:\/\/www.heise.de\/news\/Sicherheitsluecken-in-McAfee-Endpoint-Security-machen-Windows-angreifbar-4970655.html\" target=\"_blank\" rel=\"noopener noreferrer\">via<\/a>)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[English]Nutzer die McAfee Endpoint Security einsetzen, sollten das Produkt updaten. Denn Schwachstellen gef\u00e4hrden die Sicherheit von Windows. Hier einige Informationen.<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[426,161,3694],"tags":[4328,4313,3288],"class_list":["post-238045","post","type-post","status-publish","format-standard","hentry","category-sicherheit","category-virenschutz","category-windows-10","tag-sicherheit","tag-virenschutz","tag-windows-en"],"_links":{"self":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/238045","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/comments?post=238045"}],"version-history":[{"count":0,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/posts\/238045\/revisions"}],"wp:attachment":[{"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/media?parent=238045"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/categories?post=238045"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/borncity.com\/blog\/wp-json\/wp\/v2\/tags?post=238045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}