CVE-2022-1256

Severity
7.8HIGH
EPSS
0.1%
top 71.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 14
Latest updateApr 15

Description

A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges through manipulation of symbolic links.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5mcafee,llc/mcafee_agent_for_windowsunspecified5.7.6
NVDmcafee/agent< 5.7.6

🔴Vulnerability Details

2
GHSA
GHSA-qqm3-6f5j-2j3h: A local privilege escalation vulnerability in MA for Windows prior to 52022-04-15
CVEList
Improper Privilege Management in McAfee Agent for Windows2022-04-14