HomeMcafeeCVE-2021-31841

CVE-2021-31841

HIGH
8.2CVSS
Published: 2021-09-22
Updated: 2024-11-21
AI Analysis

Description

A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
low
User Action
required
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-347CWE-426CWE-347CWE-426

Metadata

Primary Vendor
MCAFEE
Published
9/22/2021
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

mcafee : mcafee_agent

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2021-31841 | HIGH Severity | CVEDatabase.com | CVEDatabase.com