CVE-2020-7315General(mcafee / mcafee_agent)

LOWCVSS 6.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mcafee_agent

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
mcafee_agent

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-24: 1Technical Details · 2026-08-24: 108-24
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • DFIR Radar@DFIR_Radar
    General

    Weekly detection engineering roundup: 39 new rules and 13 updates across 8 repos target ShieldBreak exploitation, RMM abuse, macOS CVE-2026-65400, and AI agent worm propagation. Key additions this week: - Splunk added ShieldBreak exploit coverage: watch for mpclient.dll loaded outside the Defender platform, Defender events referencing \globalroot kernel object paths, and NTFS ADS creation over loopback shares (Security EventCode 5145). Companion rules flag WerMgr.exe spawning SYSTEM-integrity children and phantom DLL creation tied to CVE-2020-7315. - RMM abuse detection expanded across three repos. New Sigma rules cover Teleport Connect installer execution (Teleport Connect Setup-*.exe), registry writes under HKLM/HKCU policy paths, and DNS queries to known RMM domains. A KQL hunt correlates email bombing, Teams phishing, and subsequent RMM execution in a single query. - A KQL rule for CVE-2026-65400 on macOS hunts SSFileCopyReceiver activity, pfctl alterations, LaunchDaemon persistence, hidden root file writes, and outbound mining traffic via Defender XDR telemetry. - Python supply-chain persistence rules now track .pth file creation, http://sitecustomize.py and http://usercustomize.py drops (as seen in VIPERTUNNEL), and outbound connections during package builds. A separate rule monitors Event 4663 for reads against accessTokens.json and TokenCache.dat. #DFIR_Radar

    Post summary

    The post discloses detection rule details for CVE-2026-65400 without any PoC, exploit code, patch guidance, or evidence of active exploitation.

    10000238
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmcafeemcafee_agent-windows-

Explore more