HIGH

CVE-2021-23874

Mcafee Total Protection 2021-02-10 CVSS v3.1
CVSS
7.8
KEV

Description

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

Summary dbcve.org

McAfee Total Protection contains a local privilege escalation vulnerability that allows a low-privileged local user to execute arbitrary code with elevated privileges by bypassing the product's self-defense mechanisms. The vulnerability exists in versions prior to 16.0.30 and exploits the security product's own protection mechanisms to gain SYSTEM-level access.

Mitigation

Update McAfee Total Protection to version 16.0.30 or later to patch the vulnerability. In enterprise environments, test the update against existing security policies and compatibility requirements before broad deployment.

Weakness (CWE)

CWE-269 Improper Privilege Management
CWE-732 Incorrect Permission Assignment

EPSS Score

1.03%
Probability of exploitation in next 30 days
62th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE