CVE Published: 19/01/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: trellix |
Vendor: McAfee,LLC |
Product: McAfee Agent for Windows Status : PUBLISHED
CVE-2022-0166 Description
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.
Metrics
CVSS Version: 3.1 |
Base Score: 7.8 HIGH Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H