PT-2024-4663 · Mcafee · Mcafee Security: Antivirus Vpn For Android

Published

2024-03-05

·

Updated

2024-07-03

·

CVE-2024-34405

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions: McAfee Security: Antivirus VPN for Android versions prior to 8.3.0
Description: The issue is related to improper deep link validation, which could allow an attacker to launch an arbitrary URL within the app. This could potentially lead to spoofing attacks, where a remote attacker could manipulate the app's behavior.
Recommendations: For versions prior to 8.3.0, update to version 8.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to deep links within the app to minimize the risk of exploitation.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

BDU:2024-05171
CVE-2024-34405

Affected Products

Mcafee Security: Antivirus Vpn For Android