EXPOSURES › CVE-2021-23874
CVE-2021-23874
HIGH ⌖ ON CISA KEV · EXPLOITEDMcAfee Total Protection allowed local users to escalate privileges and execute code by bypassing its self-defense mechanisms.
A local user could exploit an improper privilege management flaw to gain elevated privileges and run arbitrary code, completely bypassing McAfee's self-defense features. This is a critical failure for DIB organizations because it undermines endpoint security, violates CMMC/NIST 800-171 controls requiring robust access management and malware protection, and exposes systems to lateral movement. Organizations must verify that their McAfee deployments are patched and that self-defense features are not disabled or bypassed.
Shame score — A known privilege escalation flaw that bypassed core security features, indicating a fundamental design or implementation failure in the vendor's self-defense logic.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.
"McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense."
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."