PT-2020-3140 · Microsoft+1 · Windows+1
Published
2020-06-09
·
Updated
2021-10-19
·
CVE-2019-3588
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
McAfee VirusScan Enterprise versions 8.8 prior to Patch 14
Description
The issue is related to a Privilege Escalation vulnerability in the McTray.exe file of the Microsoft Windows client in McAfee VirusScan Enterprise. This vulnerability may allow unauthorized users to interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked. The vulnerability is associated with insufficient access control, which can be exploited to elevate privileges.
Recommendations
For McAfee VirusScan Enterprise version 8.8 prior to Patch 14, apply Patch 14 to resolve the issue. As a temporary workaround, consider restricting access to the McTray.exe file until the patch is applied.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Virusscan Enterprise
Windows