CVE-2023-24577
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
13/03/2023
Last modified:
03/03/2025
Description
McAfee Total Protection prior to 16.0.50 allows attackers to elevate user privileges due to Improper Link Resolution via registry keys. This could enable a user with lower privileges to execute unauthorized tasks.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mcafee:total_protection:*:*:*:*:*:*:*:* | 16.0.50 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html
- https://www.mcafee.com/support/?articleId=TS103397&page=shell&shell=article-view
- https://www.mcafee.com/en-us/consumer-corporate/mcafee-labs/product-security-bulletins.html
- https://www.mcafee.com/support/?articleId=TS103397&page=shell&shell=article-view



