CVE-2022-37025
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- mcafee/security scan plus
- Source
- cve@mitre.org
References
- https://attack.mitre.org/techniques/T1218/Not Applicable
- https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.htmlProduct
- https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-viewPatch, Vendor Advisory
- https://attack.mitre.org/techniques/T1218/Not Applicable
- https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.htmlProduct
- https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-viewPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.