cbcvebase.
CVE-2021-31840
published 2021-06-10

CVE-2021-31840: A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local…

PriorityP335high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
EPSS
0.35%
26.6th percentile
A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. This would result in the user gaining elevated permissions and being able to execute arbitrary code.

Affected

2 ranges
VendorProductVersion rangeFixed in
mcafeemcafee_agent>= 5.0.0 < 5.7.35.7.3
mcafee_llcmcafee_agent_for_windows>= unspecified < 5.7.35.7.3

CVSS provenance

nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.