← Zuruck zu CVEs
CVE-2021-31854
HIGH7.7
Beschreibung
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature located in the System Tree. An attacker may exploit the vulnerability to obtain a reverse shell which can lead to privilege escalation to obtain root privileges.
CVE Details
CVSS v3.1 Bewertung7.7
SchweregradHIGH
CVSS VektorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
AngriffsvektorLOCAL
KomplexitatLOW
Erforderliche PrivilegienHIGH
BenutzerinteraktionREQUIRED
Veroffentlicht1/19/2022
Zuletzt geandert2/24/2026
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
mcafee:agent
Schwachen (CWE)
CWE-78CWE-78
Referenzen
https://kc.mcafee.com/corporate/index?page=content&id=SB10378(trellixpsirt@trellix.com)
https://kc.mcafee.com/corporate/index?page=content&id=SB10378(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.