CVE-2019-3648 is a privilege escalation vulnerability affecting McAfee Total Protection 16.0.R22 and earlier, as well as McAfee Anti-Virus Plus and Internet Security. This flaw allows an authenticated administrator to execute arbitrary code by strategically placing malicious files in specific, administrator-protected locations, leveraging a DLL hijacking technique. With a CVSS score of 6.7 (Medium), the vulnerability requires high privileges but has a high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community attention with 5 mentions and 3 media articles, indicating awareness of its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 16.0.r22CPE matchmatch criteria | cpe:2.3:a:mcafee:anti-virus_plus:*:*:*:*:*:*:*:* | ||
<= 16.0.r22CPE matchmatch criteria | cpe:2.3:a:mcafee:internet_security:*:*:*:*:*:*:*:* | ||
<= 16.0r22CPE matchmatch criteria | cpe:2.3:a:mcafee:total_protection:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.