A privilege escalation vulnerability exists in McAfee Total Protection (MTP) versions prior to 16.0.R26, where local users can exploit improper handling of symbolic links to create or edit files in locations that would normally require elevated privileges. The vulnerability is triggered by running a malicious script or program that leverages symlink manipulation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a proof-of-concept (POC) local privilege escalation exploit for CVE-2020-7283, targeting McAfee Total Protection 16.0 R23 on Windows. The exploit leverages symlink attacks to achieve arbitrary file creation with elevated privileges. The main exploit logic is implemented in 'src/Exploit/Exploit.cpp', which first deletes all files in 'C:\ProgramData\McAfee\MSK\', checks that the directory is empty, and then creates a symlink from 'settingsdb.dat' to an attacker-supplied file. The exploit waits for McAfee to trigger file creation, then confirms the file is created, indicating successful exploitation. The codebase is structured into utility libraries for symlink, hardlink, and reparse point manipulation, with the exploit logic separated in its own directory. No network endpoints are present; the attack vector is purely local, requiring access to the target system. The exploit is based on and reuses code from Google's symboliclink-testing-tools.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.