Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-3648


A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.


Published

2019-11-13T09:15:10.877

Last Modified

2024-11-21T04:42:17.537

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.1 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-426

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mcafee anti-virus_plus ≤ 16.0.r22 Yes
Application mcafee internet_security ≤ 16.0.r22 Yes
Application mcafee total_protection ≤ 16.0r22 Yes

References