QID 376452

Date Published: 2022-07-13

QID 376452: McAfee Arbitrary Process Execution Vulnerability (TS103114)

McAfee Total Protection (MTP) use files provided by the Windows operating system and other trusted software companies.

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

Affected Versions:
McAfee Total Protection (MTP) prior to 16.0.30 QID Detection Logic:
This checks for vulnerable version of MTP.

On Successful Exploitation, an attacker with administrative permissions to the computer to place their malicious programs in specific locations and the MTP program would load and run them.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Please refer vendor released advisory to address these vulnerabilities. McAfee Total Protection (MTP).

    CVEs related to QID 376452

    Software Advisories
    Advisory ID Software Component Link
    TS103114 URL Logo service.mcafee.com/?articleId=TS103114&page=shell&shell=article-view