CVE-2019-3648: Implicit loading of DLLs
A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3648?
CVE-2019-3648 is a Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier.
How does CVE-2019-3648 affect McAfee products?
CVE-2019-3648 affects McAfee Anti-virus Plus, McAfee Internet Security, and McAfee Total Protection versions 16.0.R22 and earlier.
What is the severity of CVE-2019-3648?
The severity of CVE-2019-3648 is high, with a severity value of 6.7.
How can an attacker exploit CVE-2019-3648?
An attacker can exploit CVE-2019-3648 by carefully placing malicious files in specific locations protected by administrator permission, allowing them to execute arbitrary code.
Are there any fixes or patches available for CVE-2019-3648?
Yes, McAfee has released patches and fixes for CVE-2019-3648. Please refer to the references for more information.