CVE-2019-3592: MA for Windows update addresses weak directory permissions
Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2019-3592?
CVE-2019-3592 is a privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3 that allows local administrator users to potentially disable some McAfee processes.
What is the affected software?
The affected software is McAfee Agent (MA) before 5.6.1 HF3 on Windows.
How can the vulnerability be exploited?
The vulnerability can be exploited by manipulating the MA directory control and placing a carefully constructed file in the MA directory.
What is the severity of CVE-2019-3592?
The severity of CVE-2019-3592 is high with a CVSS score of 6.7.
How can I fix CVE-2019-3592?
To fix CVE-2019-3592, upgrade McAfee Agent to version 5.6.1 HF3 or later.