Privilege Escalation vulnerability in McAfee Drive Encryption (MDE)
CVE-2021-23893
8.8HIGH
Key Information:
- Vendor
- Mcafee,llc
- Status
- Mcafee Drive Encryption (mde)
- Vendor
- CVE Published:
- 1 October 2021
Summary
Privilege Escalation vulnerability in a Windows system driver of McAfee Drive Encryption (DE) prior to 7.3.0 could allow a local non-admin user to gain elevated system privileges via exploiting an unutilized memory buffer.
Affected Version(s)
McAfee Drive Encryption (MDE) < 7.3.0 HF1
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Balazs Bucsay (@xoreipeip), Principal Security Consultant from NCC Group