CVE-2019-3652: McAfee Endpoint Security
Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.
Affected products
- McAfee Endpoint Security: from 10.5.0, up to and including 10.5.5; from 10.6.0, before 10.6.1 (fixed in 10.6.1); version 10.6.1 only
Published 2019-10-09. Last modified 2026-06-17.