CVE-2019-3588: Using VSE to bypass Windows Credentials on Lock screen
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3588?
CVE-2019-3588 has a medium severity rating due to its ability to allow unauthorized users to bypass user privilege restrictions.
How do I fix CVE-2019-3588?
To fix CVE-2019-3588, you should update McAfee VirusScan Enterprise to version 8.8 Patch 14 or later.
What software is affected by CVE-2019-3588?
CVE-2019-3588 affects McAfee VirusScan Enterprise version 8.8 prior to Patch 14.
Can CVE-2019-3588 be exploited remotely?
CVE-2019-3588 cannot be exploited remotely as it requires local access to the machine.
What effect does CVE-2019-3588 have on the system?
CVE-2019-3588 allows unauthorized interaction with the On-Access Scan Messages during a locked Windows login screen.