CVE-2021-23874

CVE Published 2021-02-10
Related CWE(s) CWE-732: Incorrect Permission Assignment for Critical Resource, CWE-269: Improper Privilege Management
Related Vendor(s) mcafee
Related Product(s) total_protection
Exploitation Reported (CISA KEV) 2021-11-03
CVSS 3 Base Score 8.2 (HIGH)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector LOCAL

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References