Skip to content
COOEY

EXPOSURES › CVE-2021-23874

CVE-2021-23874

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2021-23874 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildrceprivilege-escalationunpatched

McAfee Total Protection allowed local users to escalate privileges and execute code by bypassing its self-defense mechanisms.

A local user could exploit an improper privilege management flaw to gain elevated privileges and run arbitrary code, completely bypassing McAfee's self-defense features. This is a critical failure for DIB organizations because it undermines endpoint security, violates CMMC/NIST 800-171 controls requiring robust access management and malware protection, and exposes systems to lateral movement. Organizations must verify that their McAfee deployments are patched and that self-defense features are not disabled or bypassed.

Shame score — A known privilege escalation flaw that bypassed core security features, indicating a fundamental design or implementation failure in the vendor's self-defense logic.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.80
McAfee's vulnerability was confirmed as critical and exploited, indicating severe security failure.
cooey ↗ severe-fallout -0.90
Critical flaw confirmed
"McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense."
cvefeed.io ↗ severe-fallout -0.90
Confirmed exploitation
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
www.ransomware.live ↗ severe-fallout -0.50
Neutral listing
app.opencve.io ↗ severe-fallout -0.50
Neutral listing
cvedb.shodan.io ↗ severe-fallout -0.50
Neutral listing
support.apple.com ↗ severe-fallout +0.00
Irrelevant
AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.