CVE-2024-49592
Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-49592?
CVE-2024-49592 is classified as a local privilege escalation vulnerability.
How do I fix CVE-2024-49592?
To fix CVE-2024-49592, you should update to the latest version of McAfee Total Protection that addresses this vulnerability.
Who can exploit CVE-2024-49592?
CVE-2024-49592 can be exploited by an adversary or a knowledgeable user with local access.
What type of attack is associated with CVE-2024-49592?
CVE-2024-49592 is associated with DLL-squatting attacks.
What software is affected by CVE-2024-49592?
CVE-2024-49592 affects the legacy trial installer software of McAfee Total Protection.