VulnerabilityModified
CVE-2019-3587
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.
MEDIUM 6.5EPSS 1.37%
Does this matter?
Lower severity and a low EPSS score (1.37%). Track it; it rarely justifies an emergency change on its own.
Description
DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.
- CVSS 3.0
- 6.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 1.37% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-426
- Affected
- mcafee/total protection
- Source
- trellixpsirt@trellix.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.