CVE-2021-23874
Description
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
Summary dbcve.org
McAfee Total Protection contains a local privilege escalation vulnerability that allows a low-privileged local user to execute arbitrary code with elevated privileges by bypassing the product's self-defense mechanisms. The vulnerability exists in versions prior to 16.0.30 and exploits the security product's own protection mechanisms to gain SYSTEM-level access.
Mitigation
Update McAfee Total Protection to version 16.0.30 or later to patch the vulnerability. In enterprise environments, test the update against existing security policies and compatibility requirements before broad deployment.