Unquoted service path vulnerability in McAfee Endpoint Product Removal (EPR) Tool prior to 21.2 allows local administrators to execute arbitrary code, with higher-level privileges, via execution from a compromised folder. The tool did not enforce and protect the execution path. Local admin privileges are required to place the files in the required location.
References
Configurations
History
21 Nov 2024, 05:51
Type | Values Removed | Values Added |
---|---|---|
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10351 - |
07 Nov 2023, 03:30
Type | Values Removed | Values Added |
---|---|---|
References | () https://kc.mcafee.com/corporate/index?page=content&id=SB10351 - |
Information
Published : 2021-03-15 19:15
Updated : 2024-11-21 05:51
NVD link : CVE-2021-23879
Mitre link : CVE-2021-23879
CVE.ORG link : CVE-2021-23879
JSON object : View
Products Affected
mcafee
- endpoint_product_removal_tool
CWE
CWE-428
Unquoted Search Path or Element