HIGH🇵🇱 Wersja polska

CVE-2022-1256

CVSS 7.8v3.1pub. 2022-04-14upd. 2024-11-21

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges through manipulation of symbolic links.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Mcafee Agent

    APP
    Mcafee
    < 5.7.6
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2018-6703CRITICAL9.8PL ✓same product

Use-after-free w McAfee Agent — RCE przez zdalny logging

CVE-2022-2313HIGH8.2same product

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users t...

CVE-2022-1258HIGH8.4same product

A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be ex...

CVE-2022-0166HIGH7.8same product

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during ...

CVE-2021-31854HIGH7.7same product

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject...