Security News > 2022 > January > McAfee Agent bug lets hackers run code with Windows SYSTEM privileges

McAfee Agent bug lets hackers run code with Windows SYSTEM privileges
2022-01-21 13:22

McAfee has patched a security vulnerability discovered in the company's McAfee Agent software for Windows enabling attackers to escalate privileges and execute arbitrary code with SYSTEM privileges.

McAfee Agent is a client-side component of McAfee ePolicy Orchestrator that downloads and enforces endpoint policies and deploys antivirus signatures, upgrades, patches, and new products on enterprise endpoints.

All McAfee Agent versions before 5.7.5 are vulnerable and allow unprivileged attackers to run code using NT AUTHORITYSYSTEM account privileges, the highest level of privileges on a Windows system, used by the OS and OS services.

"McAfee Agent contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges."

In September 2021, the company patched another McAfee Agent privilege escalation bug discovered by Tenable security researcher Clément Notin that allowed local users to execute arbitrary code and kill the antivirus.

McAfee fixed a security vulnerability impacting all editions of its Antivirus software for Windows and allowing potential attackers to escalate privileges and execute code with SYSTEM account authority.


News URL

https://www.bleepingcomputer.com/news/security/mcafee-agent-bug-lets-hackers-run-code-with-windows-system-privileges/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Mcafee 132 54 325 178 32 589