First published: Fri Sep 13 2019(Updated: )
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Free Antivirus Trial 16.0.R18 and earlier allows local users to execute arbitrary code via execution from a compromised folder placed by an attacker with administrator rights.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Total Protection | <=16.0.r18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2019-3646.
The severity level of CVE-2019-3646 is medium with a value of 6.5.
The McAfee Total Protection (MTP) Free Antivirus Trial version 16.0.R18 and earlier is affected by CVE-2019-3646.
A local user with administrator rights can exploit CVE-2019-3646 by executing arbitrary code from a compromised folder.
Yes, you can refer to the documentation available at http://service.mcafee.com/FAQDocument.aspx?&id=TS102968 for more information about CVE-2019-3646.