CVE-2018-6674

MEDIUM

Mcafee Virusscan Enterprise - Privilege Escalation

Title source: rule
STIX 2.1

Description

Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 13 allows local users to spawn unrelated processes with elevated privileges via the system administrator granting McTray.exe elevated privileges (by default it runs with the current user's privileges).

Scores

CVSS v3 6.8
EPSS 0.0002
EPSS Percentile 6.0%
Attack Vector PHYSICAL
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-274 CWE-269 CWE-264 CWE-311
Status published
Products (1)
mcafee/virusscan_enterprise 8.8.0
Published May 25, 2018
Tracked Since Feb 18, 2026