PT-2023-4542 · Mcafee · Mcafee Safe Connect
Published
2023-08-17
·
Updated
2023-08-25
·
CVE-2023-40352
CVSS v2.0
8.3
High
| Vector | AV:N/AC:L/Au:M/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
McAfee Safe Connect versions prior to 2.16.1.126
Description
The issue is related to an uncontrolled search path element, which may allow an adversary with system privileges to achieve privilege escalation by loading arbitrary DLLs. This can be exploited by a local attacker to escalate privileges on affected installations of McAfee Safe Connect VPN. An attacker must first obtain the ability to execute system-level commands.
Recommendations
For versions prior to 2.16.1.126, update to version 2.16.1.126 or later to resolve the issue. As a temporary workaround, consider restricting the loading of arbitrary DLLs to minimize the risk of exploitation.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Safe Connect