First published: Fri Nov 15 2024(Updated: )
Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Total Protection |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-49592 is classified as a local privilege escalation vulnerability.
To fix CVE-2024-49592, you should update to the latest version of McAfee Total Protection that addresses this vulnerability.
CVE-2024-49592 can be exploited by an adversary or a knowledgeable user with local access.
CVE-2024-49592 is associated with DLL-squatting attacks.
CVE-2024-49592 affects the legacy trial installer software of McAfee Total Protection.