Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-37025


An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file.


Published

2022-08-18T13:15:08.010

Last Modified

2024-11-21T07:14:18.670

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-269

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mcafee security_scan_plus < 4.1.262.1 Yes

References