CVE-2019-3587

HIGH

McAfee Total Protection < 16.0.18 - DLL Search Order Hijacking

Title source: llm
STIX 2.1

Description

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0044
EPSS Percentile 63.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-426
Status published
Products (1)
mcafee/total_protection < 16.0.18
Published Jan 23, 2019
Tracked Since Feb 18, 2026