CVE-2023-40352: High severity mcafee safe connect vpn vulnerability
Published Aug 21, 2023
·Updated
McAfee Safe Connect before 2.16.1.126 may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs.
Affected Software
1 affected component
McAfee Safe Connect<2.16.1.126
Event History
Aug 21, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this McAfee Safe Connect vulnerability?
The vulnerability ID for this McAfee Safe Connect vulnerability is CVE-2023-40352.
2
What is the severity of CVE-2023-40352?
The severity of CVE-2023-40352 is high with a CVSS score of 7.2.
3
What is the affected software for CVE-2023-40352?
The affected software for CVE-2023-40352 is McAfee Safe Connect version up to 2.16.1.126.
4
How can an adversary achieve privilege escalation in McAfee Safe Connect before version 2.16.1.126?
An adversary with system privileges can achieve privilege escalation by loading arbitrary DLLs.
5
Where can I find more information about CVE-2023-40352?
More information about CVE-2023-40352 can be found on the McAfee Labs Product Security Bulletins page and the McAfee Support article TS103462.