CVE-2022-43751

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
23/11/2022
Last modified:
29/04/2025

Description

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:total_protection:*:*:*:*:*:*:*:* 16.0.49 (excluding)