CVE-2018-6674

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:mcafee:virusscan_enterprise:8.8.0:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

07 Nov 2023, 03:00

Type Values Removed Values Added
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10237 - Third Party Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10237 -

Information

Published : 2018-05-25 13:29

Updated : 2023-11-07 03:00


NVD link : CVE-2018-6674

Mitre link : CVE-2018-6674


JSON object : View

Products Affected

microsoft

  • windows

mcafee

  • virusscan_enterprise
CWE
CWE-311

Missing Encryption of Sensitive Data