CVE-2021-23874: McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
Other sources
McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this McAfee Total Protection vulnerability?
The vulnerability ID for this McAfee Total Protection vulnerability is CVE-2021-23874.
What is the title of this vulnerability?
The title of this vulnerability is McAfee Total Protection (MTP) Improper Privilege Management Vulnerability.
What is the description of this vulnerability?
The description of this vulnerability is Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
Which software is affected by this vulnerability?
This vulnerability affects McAfee Total Protection (MTP) prior to version 16.0.30.
What is the severity of CVE-2021-23874?
The severity of CVE-2021-23874 is high with a CVSS score of 7.8.
How does CVE-2021-23874 impact McAfee Total Protection?
CVE-2021-23874 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense in McAfee Total Protection (MTP).
Is there a fix available for CVE-2021-23874?
Yes, a fix is available for CVE-2021-23874. Users should update McAfee Total Protection to version 16.0.30 or later.
Where can I find more information about CVE-2021-23874?
More information about CVE-2021-23874 can be found at the following link: http://service.mcafee.com/FAQDocument.aspx?&id=TS103114
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
This vulnerability is associated with CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-269 (Improper Privilege Management).