
CVE-2023-0221
https://notcve.org/view.php?id=CVE-2023-0221
13 Jan 2023 — Product security bypass vulnerability in ACC prior to version 8.3.4 allows a locally logged-in attacker with administrator privileges to bypass the execution controls provided by ACC using the utilman program. • https://kcm.trellix.com/corporate/index?page=content&id=SB10370 • CWE-269: Improper Privilege Management •

CVE-2022-43751
https://notcve.org/view.php?id=CVE-2022-43751
22 Nov 2022 — McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges. McAfee Total Protection anterior a la versión 16.0.49 contiene una vulnerabilidad de elemento de ruta de búsqueda no controlada debido al uso de una variable que apunta a un subdirectorio que puede ser co... • https://mcafee.com • CWE-427: Uncontrolled Search Path Element •

CVE-2022-2188 – DXL Broker privilege escalation vulnerability
https://notcve.org/view.php?id=CVE-2022-2188
07 Nov 2022 — Privilege escalation vulnerability in DXL Broker for Windows prior to 6.0.0.280 allows local users to gain elevated privileges by exploiting weak directory controls in the logs directory. This can lead to a denial-of-service attack on the DXL Broker. Una vulnerabilidad de escalada de privilegios en DXL Broker para Windows anterior a 6.0.0.280 permite a los usuarios locales obtener privilegios elevados al explotar controles de directorio débiles en el directorio de registros. Esto puede provocar un ataque de... • https://kcm.trellix.com/corporate/index?page=content&id=SB10383 • CWE-732: Incorrect Permission Assignment for Critical Resource •

CVE-2022-3339 – Reflected XSS in Trellix ePO server
https://notcve.org/view.php?id=CVE-2022-3339
18 Oct 2022 — A reflected cross-site scripting (XSS) vulnerability in ePO prior to 5.10 Update 14 allows a remote unauthenticated attacker to potentially obtain access to an ePO administrator's session by convincing the authenticated ePO administrator to click on a carefully crafted link. This would lead to limited access to sensitive information and limited ability to alter some information in ePO. Una vulnerabilidad de tipo cross-site scripting (XSS) reflejado en ePO versiones anteriores a la actualización 5.10 14, per... • https://kcm.trellix.com/corporate/index?page=content&id=SB10387 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2022-3338 – XXE in Trellix ePO server
https://notcve.org/view.php?id=CVE-2022-3338
18 Oct 2022 — An External XML entity (XXE) vulnerability in ePO prior to 5.10 Update 14 can lead to an unauthenticated remote attacker to potentially trigger a Server Side Request Forgery attack. This can be exploited by mimicking the Agent Handler call to ePO and passing the carefully constructed XML file through the API. Una vulnerabilidad de tipo External XML entity (XXE) en ePO versiones anteriores a la actualización 5.10 14, puede conllevar a que un atacante remoto no autenticado desencadene potencialmente un ataque... • https://kcm.trellix.com/corporate/index?page=content&id=SB10387 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2022-2330 – XXE vulnerability in DLP Endpoint for Windows
https://notcve.org/view.php?id=CVE-2022-2330
30 Aug 2022 — Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly. La vulnerabilidad de restricción inadecuada de la referencia a entidades externas XML en DLP Endpoint para Windows anterior a la versión 11.9.100 permite a un atacante remoto hacer que el age... • https://kcm.trellix.com/corporate/index?page=content&id=SB10386 • CWE-611: Improper Restriction of XML External Entity Reference •

CVE-2022-37025
https://notcve.org/view.php?id=CVE-2022-37025
18 Aug 2022 — An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file. Una vulnerabilidad de administración de privilegios inapropiada en McAfee Security Scan Plus (MSS+) versiones anteriores a 4.1.262.1 podría perm... • https://attack.mitre.org/techniques/T1218 • CWE-269: Improper Privilege Management •

CVE-2022-2313 – DLL high jacking in Trellix Agent
https://notcve.org/view.php?id=CVE-2022-2313
27 Jul 2022 — A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed. Una vulnerabilidad de secuestro de DLL en el instalador inteligente de MA para Windows versiones anteriores a 5.7.7, que permite a usuarios locales ejecutar código arbitrario y obtener privilegios superiores por medio de la colocación cuidad... • https://kcm.trellix.com/corporate/index?page=content&id=SB10385&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US • CWE-427: Uncontrolled Search Path Element •

CVE-2022-1823 – McAfee MCPR privilege escalation
https://notcve.org/view.php?id=CVE-2022-1823
20 Jun 2022 — Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code, through not correctly checking the integrity of the configuration file. Una vulnerabilidad de administración de privilegios inapropiada en McAfee Consumer Product Removal Tool versiones anterior... • https://service.mcafee.com/?articleId=TS103318&page=shell&shell=article-view • CWE-269: Improper Privilege Management •

CVE-2022-1824 – McAfee MCPR privilege escalation
https://notcve.org/view.php?id=CVE-2022-1824
20 Jun 2022 — An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee. Una vulnerabilidad de ruta de búsqueda no controlada en McAfee Consumer Product Removal Tool versiones anteriores a 10.4.128, podría per... • https://service.mcafee.com/?articleId=TS103318&page=shell&shell=article-view • CWE-427: Uncontrolled Search Path Element •