PT-2019-4296 · Mcafee · Mcafee Total Protection

Published

2019-10-25

·

Updated

2020-08-24

·

CVE-2019-3636

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Total Protection versions 16.0.R21 and earlier
Description A File Masquerade vulnerability allows an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry and possibly replace excluded files with potential malware without being detected. The issue is related to a lack of protection for service data, which can be exploited to gain unauthorized access to the list of excluded files and modify it.
Recommendations For McAfee Total Protection versions 16.0.R21 and earlier, update to a version later than 16.0.R21 to resolve the issue. At the moment, there is no information about other specific fixes for this vulnerability.

Fix

Information Disclosure

Cleartext Storage of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-00011
CVE-2019-3636

Affected Products

Mcafee Total Protection