CVE-2019-3653: McAfee Endpoint Security

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper access control vulnerability in Configuration tool in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to gain access to security configuration via unauthorized use of the configuration tool.

Affected products

  • McAfee Endpoint Security: from 10.5.0, up to and including 10.5.5; from 10.6.0, before 10.6.1 (fixed in 10.6.1); version 10.16.1 only

Published 2019-10-09. Last modified 2026-06-17.