First published: Wed May 12 2021(Updated: )
Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Total Protection | <16.0.32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23872 is a Privilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to version 16.0.32.
CVE-2021-23872 allows a local user to gain elevated privileges by manipulating a symbolic link in the IOCTL interface of McAfee Total Protection.
An attacker needs local access to the system to exploit CVE-2021-23872 by manipulating a symbolic link in the IOCTL interface.
CVE-2021-23872 has a severity score of 7.8 (high).
To fix CVE-2021-23872, users should update McAfee Total Protection to version 16.0.32 or later.