PT-2023-4542 · Mcafee · Mcafee Safe Connect
CVE-2023-40352
·
Publicado
2023-08-17
·
Atualizado
2023-08-25
CVSS v2.0
8.3
Alta
| Vetor | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
McAfee Safe Connect versions prior to 2.16.1.126
Description
The issue is related to an uncontrolled search path element, which may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. This can be exploited by a local attacker to escalate privileges on affected installations of McAfee Safe Connect VPN. An attacker must first obtain the ability to execute system-level commands.
Recommendations
For versions prior to 2.16.1.126, update to version 2.16.1.126 or later to resolve the issue. As a temporary workaround, consider restricting the loading of arbitrary DLLs to minimize the risk of exploitation.
Correção
Uncontrolled Search Path Element
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mcafee Safe Connect