CVE-2019-3646: McAfee Total Protection - Free Antivirus Trial: DLL Search Order Hijacking vulnerability
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbitrary code via execution from a compromised folder placed by an attacker with administrator rights.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-3646.
What is the severity level of CVE-2019-3646?
The severity level of CVE-2019-3646 is medium with a value of 6.5.
Which software is affected by CVE-2019-3646?
The McAfee Total Protection (MTP) Free Antivirus Trial version 16.0.R18 and earlier is affected by CVE-2019-3646.
How can a local user exploit CVE-2019-3646?
A local user with administrator rights can exploit CVE-2019-3646 by executing arbitrary code from a compromised folder.
Is there any reference documentation available for CVE-2019-3646?
Yes, you can refer to the documentation available at http://service.mcafee.com/FAQDocument.aspx?&id=TS102968 for more information about CVE-2019-3646.