CVE-2022-37025
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file.
Una vulnerabilidad de administración de privilegios inapropiada en McAfee Security Scan Plus (MSS+) versiones anteriores a 4.1.262.1 podría permitir a un usuario local modificar un archivo de configuración y llevar a cabo un ataque de tipo LOLBin (Living off the land). Esto podía resultar en que el usuario consiguiera permisos elevados y pudiera ejecutar código arbitrario debido a una falta de comprobación de la integridad del archivo de configuración.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-07-29 CVE Reserved
- 2022-08-18 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-269: Improper Privilege Management
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://attack.mitre.org/techniques/T1218 | Not Applicable | |
https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.html | Product |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-view | 2022-08-19 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Security Scan Plus Search vendor "Mcafee" for product "Security Scan Plus" | < 4.1.262.1 Search vendor "Mcafee" for product "Security Scan Plus" and version " < 4.1.262.1" | - |
Affected
|