CVE-2021-23874
KEVmassLocal Privilege Escalation in McAfee Total Protection Bypasses Self-Defense
CISA: McAfee Total Protection (MTP) Improper Privilege Management Vulnerability
McAfee Total Protection (MTP) prior to version 16.0.30 contains an improper privilege management flaw (CWE-269/CWE-732) that allows arbitrary process execution. A local user with low privileges can trigger it to execute arbitrary code that bypasses MTP's self-defense mechanism, which normally protects the security software from tampering. Successful exploitation grants elevated privileges on the endpoint, with high impact to confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector). Any endpoint running an affected MTP build is exposed, particularly machines with multiple or untrusted local users. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating known exploitation in the wild, while EPSS estimates a 1.0% probability of exploitation in the next 30 days (62nd percentile) and no public proof-of-concept is known.
What to do: Upgrade McAfee Total Protection to version 16.0.30 or later per vendor instructions, as required for KEV-listed vulnerabilities. Inventory endpoints for MTP builds older than 16.0.30, prioritizing shared or multi-user systems where low-privileged local users can run code. Until patched, limit local code execution by untrusted users on affected endpoints.
| McAfee Total Protection (MTP) | prior to 16.0.30 (fixed in 16.0.30) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
- Affected
- McAfee McAfee Total Protection (MTP)
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- mcafee
- Products
- total protection
- Weakness
- CWE-269, CWE-732
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.