Improper access control vulnerability in the repair...
High severity
Unreviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Nov 24, 2023
Description
Published by the National Vulnerability Database
Sep 22, 2021
Published to the GitHub Advisory Database
May 24, 2022
Last updated
Nov 24, 2023
Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.
References