A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: trellix
Published: 2022-01-19T11:05:11
Updated: 2022-01-20T23:06:12
Reserved: 2022-01-10T00:00:00
Link: CVE-2022-0166
JSON object: View
NVD Information
Status : Modified
Published: 2022-01-19T11:15:07.923
Modified: 2023-11-07T03:41:07.420
Link: CVE-2022-0166
JSON object: View
Redhat Information
No data.
CWE