Skip to main content

Uncontrolled Search Path Element

CVE-2019-3667

Severity Medium
Score 6.6/10

Summary

DLL Search Order Hijacking vulnerability in the Microsoft Windows client in McAfee Tech Check 3.0.0.17 and earlier allows local users to execute arbitrary code via the local folder placed there by an attacker.

  • HIGH
  • LOCAL
  • HIGH
  • CHANGED
  • REQUIRED
  • LOW
  • LOW
  • LOW

CWE-427 - Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

References

Advisory Timeline

  • Published