First published: Wed Jun 10 2020(Updated: )
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Virusscan Enterprise | =8.8 | |
Mcafee Virusscan Enterprise | =8.8-patch1 | |
Mcafee Virusscan Enterprise | =8.8-patch10 | |
Mcafee Virusscan Enterprise | =8.8-patch11 | |
Mcafee Virusscan Enterprise | =8.8-patch12 | |
Mcafee Virusscan Enterprise | =8.8-patch13 | |
Mcafee Virusscan Enterprise | =8.8-patch2 | |
Mcafee Virusscan Enterprise | =8.8-patch3 | |
Mcafee Virusscan Enterprise | =8.8-patch4 | |
Mcafee Virusscan Enterprise | =8.8-patch5 | |
Mcafee Virusscan Enterprise | =8.8-patch6 | |
Mcafee Virusscan Enterprise | =8.8-patch7 | |
Mcafee Virusscan Enterprise | =8.8-patch8 | |
Mcafee Virusscan Enterprise | =8.8-patch9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3588 has a medium severity rating due to its ability to allow unauthorized users to bypass user privilege restrictions.
To fix CVE-2019-3588, you should update McAfee VirusScan Enterprise to version 8.8 Patch 14 or later.
CVE-2019-3588 affects McAfee VirusScan Enterprise version 8.8 prior to Patch 14.
CVE-2019-3588 cannot be exploited remotely as it requires local access to the machine.
CVE-2019-3588 allows unauthorized interaction with the On-Access Scan Messages during a locked Windows login screen.