PT-2023-4542 · Mcafee · Mcafee Safe Connect

CVE-2023-40352

·

Publicado

2023-08-17

·

Atualizado

2023-08-25

CVSS v2.0

8.3

Alta

VetorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee Safe Connect versions prior to 2.16.1.126
Description The issue is related to an uncontrolled search path element, which may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. This can be exploited by a local attacker to escalate privileges on affected installations of McAfee Safe Connect VPN. An attacker must first obtain the ability to execute system-level commands.
Recommendations For versions prior to 2.16.1.126, update to version 2.16.1.126 or later to resolve the issue. As a temporary workaround, consider restricting the loading of arbitrary DLLs to minimize the risk of exploitation.

Correção

Uncontrolled Search Path Element

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-04947
CVE-2023-40352
ZDI-23-1158

Produtos afetados

Mcafee Safe Connect