PT-2020-3139 · Mcafee · Mcafee Virusscan Enterprise

Published

2020-06-09

·

Updated

2021-10-19

·

CVE-2019-3585

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee VirusScan Enterprise versions 8.8 prior to Patch 14
Description The issue is related to a Privilege Escalation vulnerability in the McTray.exe file of McAfee VirusScan Enterprise. This vulnerability may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges by running McAfee Tray with elevated privileges. The vulnerability is associated with insufficient access control.
Recommendations For McAfee VirusScan Enterprise version 8.8 prior to Patch 14, apply Patch 14 to resolve the issue. As a temporary workaround, consider restricting the use of the McTray.exe file to minimize the risk of exploitation. Avoid running McAfee Tray with elevated privileges until the issue is resolved.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03433
CVE-2019-3585

Affected Products

Mcafee Virusscan Enterprise