Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gq64-xh72-gm28

Опубликовано: 20 янв. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.8

Описание

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

EPSS

Процентиль: 19%
0.00059
Низкий

7.8 High

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 7.8
nvd
около 4 лет назад

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

CVSS3: 7.8
fstec
около 4 лет назад

Уязвимость антивирусного программного средства McAfee Agent, связанная с ошибками управления привилегиями, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 19%
0.00059
Низкий

7.8 High

CVSS3

Дефекты

CWE-269