Improper access control vulnerability in ESconfigTool.exe in McAfee Endpoint Security (ENS) for Windows all current versions allows local administrator to alter ENS configuration up to and including disabling all protection offered by ENS via insecurely implemented encryption of configuration for export and import.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.