#VU29035 Permissions, Privileges, and Access Controls in McAfee VirusScan - CVE-2019-3588

 

#VU29035 Permissions, Privileges, and Access Controls in McAfee VirusScan - CVE-2019-3588

Published: June 16, 2020


Vulnerability identifier: #VU29035
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-3588
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
McAfee VirusScan
Software vendor:
McAfee

Description

The vulnerability allows a local attacker to escalate privileges on the system.

The vulnerability exists due to application does not properly impose security restrictions in Microsoft Windows client (McTray.exe). An attacker with physical access can interact with the On-Access Scan Messages - Threat Alert Window when the Windows Login Screen is locked. 


Remediation

Install updates from vendor's website.

External links