Categories: Technology

McAfee bug: Hackers Can penetrate Using Windows system privileges

A critical vulnerability in McAfee Agent allows hackers to penetrate networks and gain full Windows system privileges. There is already an update that fixes the serious vulnerability. That report comes from the Bleeping Computer. Accordingly, there is a vulnerability in McAfee Enterprise (renamed Trellix) that can be exploited on a large scale by hackers.

The vulnerability was discovered in the McAfee Agent software for Windows. McAfee Agent is a client component of McAfee ePolicy Orchestrator (McAfee ePO) that downloads and enforces endpoint policies, and delivers antivirus signatures, upgrades, patches, and new products to enterprise endpoints. You can basically put all the important security features in the hands of the software, but the security loopholes that have been discovered have disabled the defenses.

Local privilege can be used

With the release of McAfee Agent 5.7.5, the company has fixed a serious Local Privilege Elevation (LPE) vulnerability known as CVE-2022-0166. All McAfee Agent versions prior to 5.7.5 are said to be vulnerable, allowing attackers to execute code with NT AUTHORITYSYSTEM account privileges, the highest level of privileges on a Windows system used by the operating system itself and operating system services.

“McAfee Agent, which ships with several McAfee products such as McAfee Endpoint Security, includes an OpenSSL component that specifies an OPENSSLDIR variable as a subfolder that can be controlled by an unauthorized user on Windows,” explains security researcher Will Dormann, who discovered the vulnerability. and reported this to the company. “McAfee Agent includes a privileged service that uses this OpenSSL component. A user who can place a specially crafted openssl.cnf file in an appropriate path may be able to run arbitrary code with SYSTEM privileges.”

Hackers can gain full access

Once hackers have done that, they can access all components for almost free and can install malware and steal data without being detected. However, the vulnerability can only be exploited at a local level, which makes exploitation a bit more difficult in the beginning. It is unknown to what extent the vulnerability is actively exploited.

Recent Posts

Trump is now imposing 100 percent tariffs on drone imports

The US government under Donald Trump is imposing massive tariffs on the import of drones.…

2 days ago

Neagley: New trailer for the Reacher spin-off released

After a first teaser video at the end of July, Amazon Prime Video is now…

2 days ago

5 Reasons Large Format Lenticular Printing Commands Attention In Any Space

Imagine the following: a booth, storefront, or lobby wall that appears to be one of…

2 days ago

Tank vs. Tankless Water Heaters: Which is the best in Edmonton Winters?

When it comes to selecting a water heater in Edmonton, it is not about selecting…

2 days ago

BMI vs Body Composition: Why Clinicians Are Rethinking the Scale’s Favorite Number

In January 2025, a group of more than 50 international experts assembled by The Lancet Diabetes…

2 days ago

Austin Fence Installation Contracts: 12 Clauses Homeowners Should Check in 2026

A fence proposal becomes useful only when it explains what will be built, who owns…

3 days ago