CVE-2022-1824
McAfee MCPR privilege escalation
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.
Una vulnerabilidad de ruta de búsqueda no controlada en McAfee Consumer Product Removal Tool versiones anteriores a 10.4.128, podría permitir a un atacante local llevar a cabo un ataque de sideloading usando un nombre de archivo específico. Esto podría resultar en que el usuario obtuviera permisos elevados y pudiera ejecutar código arbitrario, ya que no había suficientes comprobaciones sobre el ejecutable firmado por McAfee
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-23 CVE Reserved
- 2022-06-20 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://service.mcafee.com/?articleId=TS103318&page=shell&shell=article-view | 2023-11-15 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Consumer Product Removal Tool Search vendor "Mcafee" for product "Consumer Product Removal Tool" | < 10.4.128 Search vendor "Mcafee" for product "Consumer Product Removal Tool" and version " < 10.4.128" | - |
Affected
|