Severity
4.4MEDIUM
EPSS
0.1%
top 71.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 12
Latest updateMay 24

Description

Improper access control vulnerability in masvc.exe in McAfee Agent (MA) prior to 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 0.5 | Impact: 5.2

Affected Packages2 packages

NVDmcafee/agent5.5.05.5.4+1
CVEListV5mcafee,_llc/mcafee_agent_(ma)5.6.x5.6.4

🔴Vulnerability Details

2
GHSA
GHSA-c587-ph7f-xxrj: Improper access control vulnerability in masvc2022-05-24
CVEList
Improper access control vulnerability in McAfee Agent2020-03-12