PT-2021-15577 · Mcafee · Mcafee Total Protection

Abdelhamid Naceri

·

Published

2021-02-10

·

Updated

2022-05-03

·

CVE-2021-23873

CVSS v3.1

7.8

High

VectorAV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: McAfee Total Protection versions prior to 16.0.30
Description: The issue allows a local user to gain elevated privileges and perform arbitrary file deletion as the SYSTEM user, potentially causing Denial of Service. This is achieved via manipulating Junction link, after enumerating certain files, at a specific time.
Recommendations: For versions prior to 16.0.30, update to version 16.0.30 or later to resolve the issue. As a temporary workaround, consider restricting access to the Junction link manipulation functionality to minimize the risk of exploitation.

Fix

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-23873
ZDI-21-175

Affected Products

Mcafee Total Protection