PT-2023-4542 · Mcafee · Mcafee Safe Connect

Published

2023-08-17

·

Updated

2023-08-25

·

CVE-2023-40352

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee Safe Connect versions prior to 2.16.1.126
Description The issue is related to an uncontrolled search path element, which may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. This can be exploited by a local attacker to escalate privileges on affected installations of McAfee Safe Connect VPN. An attacker must first obtain the ability to execute system-level commands.
Recommendations For versions prior to 2.16.1.126, update to version 2.16.1.126 or later to resolve the issue. As a temporary workaround, consider restricting the loading of arbitrary DLLs to minimize the risk of exploitation.

Fix

Uncontrolled Search Path Element

Weakness Enumeration

Related Identifiers

BDU:2023-04947
CVE-2023-40352
ZDI-23-1158

Affected Products

Mcafee Safe Connect