PT-2023-1883 · Mcafee · Mcafee Total Protection

Published

2023-03-13

·

Updated

2025-02-27

·

CVE-2023-24578

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions McAfee Total Protection versions prior to 16.0.49
Description The issue is related to an uncontrolled search path element in McAfee Total Protection, which can be exploited to elevate user privileges due to DLL sideloading. This could enable a user with lower privileges to execute unauthorized tasks.
Recommendations For versions prior to 16.0.49, update to version 16.0.49 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2023-01484
CVE-2023-24578

Affected Products

Mcafee Total Protection