cve/2019/CVE-2019-3585.md

18 lines
886 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-3585](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3585)
![](https://img.shields.io/static/v1?label=Product&message=McAfee%20VirusScan%20Enterprise%20(VSE)&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=8.8.x%3C%208.8%20Patch%2014%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-269%3A%20Improper%20Privilege%20Management&color=brighgreen)
### Description
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10302
#### Github
No PoCs found on GitHub currently.