CVE-2018-6674 MEDIUM

CVE-2018-6674: Privilege escalation vulnerability in McAfee VSE when McTray run with elevated privileges

Vendor Mcafee, Llc
Product VirusScan Enterprise (VSE)
Weakness CWE-264
Published May 25, 2018
Last update August 5, 2024

CVSS base score

6.8/10
Attack vector Physical
Attack complexity High
Privileges required High
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).

Key dates

02Disclosure timeline

May 25, 2018 CVE published
August 5, 2024 Record updated