PT-2020-3140 · Microsoft+1 · Windows+1

Published

2020-06-09

·

Updated

2021-10-19

·

CVE-2019-3588

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee VirusScan Enterprise versions 8.8 prior to Patch 14
Description The issue is related to a Privilege Escalation vulnerability in the McTray.exe file of the Microsoft Windows client in McAfee VirusScan Enterprise. This vulnerability may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked. The vulnerability is associated with insufficient access control, which can be exploited to elevate privileges.
Recommendations For McAfee VirusScan Enterprise version 8.8 prior to Patch 14, apply Patch 14 to resolve the issue. As a temporary workaround, consider restricting access to the McTray.exe file until the patch is applied.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-03434
CVE-2019-3588

Affected Products

Mcafee Virusscan Enterprise
Windows