A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: trellix
Published: 2021-06-10T16:20:12
Updated: 2024-08-03T23:10:30.955Z
Reserved: 2021-04-27T00:00:00
Link: CVE-2021-31840
Vulnrichment
No data.
NVD
Status : Modified
Published: 2021-06-10T17:15:08.180
Modified: 2024-11-21T06:06:20.053
Link: CVE-2021-31840
Redhat
No data.