First published: Wed Nov 10 2021(Updated: )
DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to 7.3.0 HF2 (7.3.0.183) allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Drive Encryption | >=7.2.0<=7.2.10 | |
McAfee Drive Encryption | =7.3.0 | |
McAfee Drive Encryption | =7.3.0-hotfix1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-31853 is a DLL Search Order Hijacking Vulnerability in McAfee Drive Encryption (MDE) prior to version 7.3.0 HF2 (7.3.0.183) that allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.
CVE-2021-31853 affects McAfee Drive Encryption versions prior to 7.3.0 HF2 (7.3.0.183), allowing local users to execute arbitrary code and escalate privileges.
CVE-2021-31853 has a severity rating of 7.8 (High).
To fix CVE-2021-31853, update McAfee Drive Encryption to version 7.3.0 HF2 (7.3.0.183) or later.
You can find more information about CVE-2021-31853 on the McAfee Knowledge Center website: https://kc.mcafee.com/corporate/index?page=content&id=SB10374