Description
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-15374 | A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file. |
References
History
No history.
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-02T23:18:42.062Z
Reserved: 2022-01-10T00:00:00.000Z
Link: CVE-2022-0166
No data.
Status : Modified
Published: 2022-01-19T11:15:07.923
Modified: 2024-11-21T06:38:03.367
Link: CVE-2022-0166
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD