Aller au contenu

Fiche vulnérabilité

CVE-2021-31854 : faille élevée mcafee agent (CVSS 7.8)

Description

A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature located in the System Tree. An attacker may exploit the vulnerability to obtain a reverse shell which can lead to privilege escalation to obtain root privileges.

En bref

Sévérité
Élevée (CVSS 7.8)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
19 janv. 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • mcafee agent

Références

Rechercher une autre vulnérabilité dans la base CVE