CVE-2018-6674: Privilege escalation vulnerability in McAfee VSE when McTray run with elevated privileges
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
McAfee VirusScan Enterprise (VSE) 8.8to a version that resolves this vulnerability.Patch Patch 13
Event History
Frequently Asked Questions
What is CVE-2018-6674?
CVE-2018-6674 is a privilege escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13.
How does CVE-2018-6674 affect McAfee VirusScan Enterprise?
CVE-2018-6674 allows local users to spawn unrelated processes with elevated privileges in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13.
How can this vulnerability be exploited?
This vulnerability can be exploited by the system administrator granting McTray.exe elevated privileges, allowing local users to spawn unrelated processes with elevated privileges.
What is the severity of CVE-2018-6674?
CVE-2018-6674 has a severity rating of medium with a CVSS score of 3.9.
How can CVE-2018-6674 be patched?
CVE-2018-6674 can be patched by applying Patch 13 for McAfee VirusScan Enterprise (VSE) 8.8.