Fiche vulnérabilité
CVE-2021-31841 : faille élevée mcafee mcafee agent (CVSS 7.3)
Description
A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the ability to execute arbitrary code as the system user, through not checking the DLL signature.
En bref
- Sévérité
- Élevée (CVSS 7.3)
- Vecteur CVSS
- CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 22 sept. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- mcafee mcafee agent