VulnerabilityModified
CVE-2023-24577
McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys.
MEDIUM 5.5EPSS 0.28%
Does this matter?
Lower severity and a low EPSS score (0.28%). Track it; it rarely justifies an emergency change on its own.
Description
McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 0.28% probability · 21th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- mcafee/total protection
- Source
- cve@mitre.org
References
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.htmlVendor Advisory
- https://www.mcafee.com/support/?articleId=TS103397&page=shell&shell=article-viewVendor Advisory
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.htmlVendor Advisory
- https://www.mcafee.com/support/?articleId=TS103397&page=shell&shell=article-viewVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.