cve/2022/CVE-2022-0166.md
2024-06-18 02:51:15 +02:00

1.0 KiB

CVE-2022-0166

Description

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

POC

Reference

Github