Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-18722 Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as the system user, through not correctly protecting a temporary directory used in the repair process and not checking the DLL signature.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: trellix

Published:

Updated: 2024-08-03T23:10:30.809Z

Reserved: 2021-04-27T00:00:00

Link: CVE-2021-31847

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-09-22T14:15:07.563

Modified: 2024-11-21T06:06:20.813

Link: CVE-2021-31847

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.