PT-2022-14142 · Mcafee · Mcafee Consumer Product Removal Tool

Published

2022-06-20

·

Updated

2023-11-16

·

CVE-2022-1823

CVSS v3.1

7.9

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Consumer Product Removal Tool versions prior to 10.4.128
Description The issue is related to improper privilege management, which could allow a local user to modify a configuration file. This modification could lead to a LOLBin (Living off the land) attack, resulting in the user gaining elevated permissions and being able to execute arbitrary code. The vulnerability arises from the failure to correctly check the integrity of the configuration file.
Recommendations For versions prior to 10.4.128, update to version 10.4.128 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration file to prevent unauthorized modifications until the update is applied.

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2022-1823

Affected Products

Mcafee Consumer Product Removal Tool