First published: Tue Oct 26 2021(Updated: )
Privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Total Protection | <16.0.34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23877 is a privilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to version 16.0.34_x that may allow a local user to run arbitrary code as the admin user.
CVE-2021-23877 affects the trial installer of McAfee Total Protection on Windows systems prior to version 16.0.34_x.
The severity of CVE-2021-23877 is high, with a CVSS score of 7.8.
A local user can exploit CVE-2021-23877 by replacing a specific temporary file created during the installation of the trial version of McAfee Total Protection.
Yes, users should update their McAfee Total Protection software to version 16.0.34_x or later to fix the vulnerability.