First published: Wed Sep 22 2021(Updated: )
A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Mcafee Agent | <5.7.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-31841.
The severity of CVE-2021-31841 is high with a CVSS score of 7.8.
McAfee Agent for Windows versions prior to 5.7.4 are affected by CVE-2021-31841.
CVE-2021-31841 could allow a local user to perform a DLL sideloading attack, gaining elevated permissions and the ability to execute arbitrary code.
Update McAfee Agent for Windows to version 5.7.4 or later to fix CVE-2021-31841.