#VU12138 Insecure DLL loading in McAfee True Key - CVE-2018-6661
Published: April 16, 2018 / Updated: June 17, 2021
McAfee True Key
McAfee
Description
The vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in Microsoft Windows Client due to insecure .dll loading mechanism when opening files. A local attacker can place a file along with a specially crafted .dll file on a remote SBM or WebDAV share and gain root privileges.