McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Link | Tags |
---|---|
https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html | vendor advisory |
https://www.mcafee.com/support/?articleId=TS103397&page=shell&shell=article-view | vendor advisory |