CVE-2019-3636

HIGH

McAfee Total Protection < 16.0.R21 - Cleartext Storage of Sensitive Information in Windows Registry

Title source: llm
STIX 2.1

Description

A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.

References (1)

Core 1

Scores

CVSS v3 7.5
EPSS 0.0006
EPSS Percentile 19.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H

Details

CWE
CWE-312
Status published
Products (1)
mcafee/total_protection < 16.0.r21
Published Oct 28, 2019
Tracked Since Feb 18, 2026