Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2022-0166

A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.012
EPSS Ranking 78.2%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 7.2
Products affected by CVE-2022-0166
  • Mcafee » Agent » Version: N/A
    cpe:2.3:a:mcafee:agent:-
  • Mcafee » Agent » Version: 5.0.0
    cpe:2.3:a:mcafee:agent:5.0.0
  • Mcafee » Agent » Version: 5.0.1
    cpe:2.3:a:mcafee:agent:5.0.1
  • Mcafee » Agent » Version: 5.0.2
    cpe:2.3:a:mcafee:agent:5.0.2
  • Mcafee » Agent » Version: 5.0.3
    cpe:2.3:a:mcafee:agent:5.0.3
  • Mcafee » Agent » Version: 5.0.4
    cpe:2.3:a:mcafee:agent:5.0.4
  • Mcafee » Agent » Version: 5.0.5
    cpe:2.3:a:mcafee:agent:5.0.5
  • Mcafee » Agent » Version: 5.0.6
    cpe:2.3:a:mcafee:agent:5.0.6
  • Mcafee » Agent » Version: 5.5.0
    cpe:2.3:a:mcafee:agent:5.5.0
  • Mcafee » Agent » Version: 5.5.1
    cpe:2.3:a:mcafee:agent:5.5.1
  • Mcafee » Agent » Version: 5.5.2
    cpe:2.3:a:mcafee:agent:5.5.2
  • Mcafee » Agent » Version: 5.5.3
    cpe:2.3:a:mcafee:agent:5.5.3
  • Mcafee » Agent » Version: 5.6.0
    cpe:2.3:a:mcafee:agent:5.6.0
  • Mcafee » Agent » Version: 5.6.1
    cpe:2.3:a:mcafee:agent:5.6.1
  • Mcafee » Agent » Version: 5.7.1
    cpe:2.3:a:mcafee:agent:5.7.1


Contact Us

Shodan ® - All rights reserved