CVE-2019-3648

A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:anti-virus_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:total_protection:*:*:*:*:*:*:*:*

History

07 Nov 2023, 03:10

Type Values Removed Values Added
References (MISC) https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 - Exploit, Third Party Advisory () https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 -
References (CONFIRM) https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 - Vendor Advisory () https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 -

Information

Published : 2019-11-13 09:15

Updated : 2023-12-10 13:13


NVD link : CVE-2019-3648

Mitre link : CVE-2019-3648

CVE.ORG link : CVE-2019-3648


JSON object : View

Products Affected

mcafee

  • internet_security
  • anti-virus_plus
  • total_protection
CWE
CWE-426

Untrusted Search Path