First published: Wed Jan 19 2022(Updated: )
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.
Credit: psirt@mcafee.com psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Agent | <5.7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0166 is a privilege escalation vulnerability in the McAfee Agent prior to 5.7.5.
CVE-2022-0166 has a severity score of 7.8 (High).
CVE-2022-0166 affects McAfee Agent versions prior to 5.7.5.
CVE-2022-0166 can be exploited by a low privilege user to create subdirectories and execute arbitrary code.
To fix CVE-2022-0166, users should upgrade to McAfee Agent version 5.7.5 or later.