CVE-2022-1823
McAfee MCPR privilege escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper privilege management vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code, through not correctly checking the integrity of the configuration file.
Una vulnerabilidad de administración de privilegios inapropiada en McAfee Consumer Product Removal Tool versiones anteriores a 10.4.128, podría permitir a un usuario local modificar un archivo de configuración y llevar a cabo un ataque LOLBin (Living off the land). Esto podría resultar en que el usuario obtuviera permisos elevados y pudiera ejecutar código arbitrario, al no comprobar correctamente la integridad del archivo de configuración
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-23 CVE Reserved
- 2022-06-20 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://service.mcafee.com/?articleId=TS103318&page=shell&shell=article-view | 2023-11-16 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Consumer Product Removal Tool Search vendor "Mcafee" for product "Consumer Product Removal Tool" | < 10.4.128 Search vendor "Mcafee" for product "Consumer Product Removal Tool" and version " < 10.4.128" | - |
Affected
|