PT-2022-4406 · Mcafee · Mcafee Security Scan Plus
Published
2022-08-15
·
Updated
2022-08-19
·
CVE-2022-37025
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McAfee Security Scan Plus versions prior to 4.1.262.1
Description
The issue is related to improper privilege management, which could allow a local user to modify a configuration file. This modification can lead to a Living off the Land (LOLBin) attack, resulting in the user gaining elevated permissions and being able to execute arbitrary code due to the lack of an integrity check of the configuration file.
Recommendations
For versions prior to 4.1.262.1, update to version 4.1.262.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the configuration file to prevent modification until a patch is applied.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Security Scan Plus