CVE-2021-31840: DLL preload vulnerability in McAfee Agent for Windows
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-31840?
CVE-2021-31840 is a vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3.
How does CVE-2021-31840 impact McAfee Agent for Windows?
CVE-2021-31840 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs.
What is the severity of CVE-2021-31840?
The severity of CVE-2021-31840 is high, with a severity value of 7.3.
How can I fix CVE-2021-31840 in McAfee Agent for Windows?
To fix CVE-2021-31840, you need to update McAfee Agent for Windows to version 5.7.3 or later.
Where can I find more information about CVE-2021-31840?
You can find more information about CVE-2021-31840 on the official McAfee Knowledge Center website at the following link: [https://kc.mcafee.com/corporate/index?page=content&id=SB10362](https://kc.mcafee.com/corporate/index?page=content&id=SB10362)