← Back

CVE-2022-0129

nvd nist
Published: Jan 11, 2022Modified: Jun 17, 2026

JSON object

Loading...
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD

Description

Uncontrolled search path element vulnerability in McAfee TechCheck prior to 4.0.0.2 allows a local administrator to load their own Dynamic Link Library (DLL) gaining elevation of privileges to system user. This was achieved through placing the malicious DLL in the same directory that the process was run from.

Affected (1)

Products: Mcafee: Techcheck
1 product
Techcheck
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 4.0.0.2

References (2)

Source: trellixpsirt@trellix.com
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.