First published: Wed Feb 10 2021(Updated: )
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Total Protection | <16.0.30 | |
McAfee McAfee Total Protection (MTP) | ||
<16.0.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this McAfee Total Protection vulnerability is CVE-2021-23874.
The title of this vulnerability is McAfee Total Protection (MTP) Improper Privilege Management Vulnerability.
The description of this vulnerability is Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
This vulnerability affects McAfee Total Protection (MTP) prior to version 16.0.30.
The severity of CVE-2021-23874 is high with a CVSS score of 7.8.
CVE-2021-23874 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense in McAfee Total Protection (MTP).
Yes, a fix is available for CVE-2021-23874. Users should update McAfee Total Protection to version 16.0.30 or later.
More information about CVE-2021-23874 can be found at the following link: http://service.mcafee.com/FAQDocument.aspx?&id=TS103114
This vulnerability is associated with CWE-732 (Incorrect Permission Assignment for Critical Resource) and CWE-269 (Improper Privilege Management).