PT-2022-14143 · Mcafee · Mcafee Consumer Product Removal Tool

Published

2022-06-20

·

Updated

2023-11-15

·

CVE-2022-1824

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions McAfee Consumer Product Removal Tool versions prior to 10.4.128
Description An uncontrolled search path issue could allow a local attacker to perform a sideloading attack by using a specific file name, potentially resulting in elevated permissions and the execution of arbitrary code due to insufficient checks on the executable being signed.
Recommendations For versions prior to 10.4.128, update to version 10.4.128 or later to resolve the issue. As a temporary workaround, consider restricting access to the executable to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

CVE-2022-1824

Affected Products

Mcafee Consumer Product Removal Tool