CVE-2021-23874

HIGH KEV

McAfee Total Protection < 16.0.30 - Arbitrary Process Execution and Privilege Escalation via Self-Defense Bypass

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-23874 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021.

Description

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

References (2)

Core 2

Scores

CVSS v3 8.2
EPSS 0.0073
EPSS Percentile 73.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-11-03
ENISA EUVD EUVD-2021-10800
CWE
CWE-269 CWE-732
Status published
Products (1)
mcafee/total_protection < 16.0.30
Published Feb 10, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026