Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31847

Опубликовано: 22 сент. 2021
Источник: nvd
CVSS3: 8.2
CVSS3: 7.8
CVSS2: 6.9
EPSS Низкий

Описание

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:mcafee:agent:*:*:*:*:*:windows:*:*
Версия до 5.7.4 (исключая)

EPSS

Процентиль: 9%
0.00034
Низкий

8.2 High

CVSS3

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-269
CWE-427

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.

EPSS

Процентиль: 9%
0.00034
Низкий

8.2 High

CVSS3

7.8 High

CVSS3

6.9 Medium

CVSS2

Дефекты

CWE-269
CWE-427