QID 376618

Date Published: 2022-05-25

QID 376618: McAfee Agent Privilege Escalation Vulnerability (SB10382)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.

CVE-2022-1256: A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges through manipulation of symbolic links.
Affected versions:
McAfee Agent Prior to 5.7.6
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.

Successful exploitation of this vulnerability may allows a local low privileged user to gain system privileges through running the repair functionality.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Install or update to McAfee Agent 5.7.6 For more details refer SB10382

    CVEs related to QID 376618

    Software Advisories
    Advisory ID Software Component Link
    SB10382 URL Logo kc.mcafee.com/corporate/index?page=content&id=SB10382