McAfee Vulnerabilities and Affected Products
Vulnerabilities associated with McAfee Total Protection (MTP).
Products
Clear product- Network Security Management (NSM)16 vulnerabilities
- Advanced Threat Defense (ATD)12 vulnerabilities
- McAfee Web Gateway (MWG)8 vulnerabilities
- Network Data Loss Prevention (NDLP)8 vulnerabilities
- DLP ePO extension6 vulnerabilities
- ePolicy Orchestrator (ePO)6 vulnerabilities
- McAfee Total Protection (MTP)4 vulnerabilities
- True Key4 vulnerabilities
- McAfee Agent (MA) for Linux3 vulnerabilities
- Network Data Loss Prevention3 vulnerabilities
- Application and Change Control2 vulnerabilities
- Data Loss Prevention (DLP) ePO extension2 vulnerabilities
- Data Loss Prevention Endpoint (DLPe)2 vulnerabilities
- Data Loss Prevention(DLP)2 vulnerabilities
- ePolicy Orchistrator (ePO)2 vulnerabilities
- Live Safe2 vulnerabilities
- True Key (TK)2 vulnerabilities
- antivirus_vpn_for_android1 vulnerability
- Client Proxy (MCP)1 vulnerability
- Common UI (CUI)1 vulnerability
- Data Loss Prevention1 vulnerability
- Data Loss Prevention (DLP) Endpoint1 vulnerability
- Data Loss Prevention (DLP) for Windows1 vulnerability
- Database Security1 vulnerability
- Drive Encryption (MDE)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-23877MEDIUM | McAfee Total Protection (MTP) - Privilege Escalation vulnerabilityPrivilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP. CWE-269Oct 26, 2021 | CVSS6.7v3.1 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-23874HIGH | McAfee Total Protection (MTP) privilege escalation vulnerabilityArbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense. | CVSS8.2v3.1 | EPSS1.03% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7298HIGH | Total Protection (MTP) - Unexpected behavior violationUnexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially crafted object making a specific function call. CWE-20Aug 5, 2020 | CVSS7.5v3.1 | EPSS0.293% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-4028MEDIUM | SB10193 - consumer and corporate products - Maliciously misconfigured registry vulnerabilityMaliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters. CWE-74Apr 3, 2018 | CVSS5.0v3.0 | EPSS0.537% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |