A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
The LPE flaw now tracked as CVE-2019-3648 requires attackers to have Administrator privileges for exploitation. Threat actors regularly exploit DLL search-order hijacking flaws such as this as part of later stages of attacks after a machine was already infiltrated, when needing to elevate permissions to establish persistence and further compromise the targeted machine. Updates are available.
Install or update to MTP version 16.0.R22 Refresh 1.
McAfee’s software will automatically update to the latest version. If McAfee’s software has not updated yet and you want to download the latest version, go to the Product Downloads site and download the latest update for your product.