HIGH🇵🇱 Wersja polska

CVE-2022-2313

CVSS 8.2v3.1pub. 2022-07-27upd. 2024-11-21

A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
  • Mcafee Agent

    APP
    Mcafee
    < 5.7.7
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-6703CRITICAL9.8PL ✓same product

Use-after-free w McAfee Agent — RCE przez zdalny logging

CVE-2022-1258HIGH8.4same product

A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be ex...

CVE-2022-1256HIGH7.8same product

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user...

CVE-2022-0166HIGH7.8same product

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during ...

CVE-2021-31854HIGH7.7same product

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject...