CVE-2022-1824
Last modified
CVE-2022-1824 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Consumer Product Removal Tool | < 10.4.128 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-1824?
How severe is CVE-2022-1824?
How do I fix CVE-2022-1824?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-1818The Multi-page Toolkit WordPress plugin through 2.6 does not…5.4
- CVE-2022-1819A vulnerability, which was classified as problematic, was fo…4.8
- CVE-2022-1820The Keep Backup Daily plugin for WordPress is vulnerable to …6.1
- CVE-2022-1821An issue has been discovered in GitLab CE/EE affecting all v…4.3
- CVE-2022-1822The Zephyr Project Manager plugin for WordPress is vulnerabl…6.1
- CVE-2022-1823Improper privilege management vulnerability in McAfee Consum…7.8
- CVE-2022-1825Cross-site Scripting (XSS) - Reflected in GitHub repository …5.4
- CVE-2022-1826The Cross-Linker WordPress plugin through 3.0.1.9 does not h…6.5
- CVE-2022-1827The PDF24 Article To PDF WordPress plugin through 4.2.2 does…6.5
- CVE-2022-1828The PDF24 Articles To PDF WordPress plugin through 4.2.2 doe…6.5
- CVE-2022-1829The Inline Google Maps WordPress plugin through 5.11 does no…6.5
- CVE-2022-1830The Amazon Einzeltitellinks WordPress plugin through 1.3.3 d…6.5
Are you affected by CVE-2022-1824?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
