McAfee Safe Connect Security Update – 22 August 2023

McAfee has released a security update to fix a vulnerability in McAfee Safe Connect versions before 2.16.1.126.

The addressed vulnerability could allow the attacker to gain privileges and access the device that running the vulnerable software, or other connected devices by using a specially crafted “.DLL” file.

This flaw is caused by an uncontrolled search path element flaw within the configuration of OpenSSL.

McAfee Safe Connect Privilege Escalation Vulnerability (CVE-2023-40352):

  • CVSS: 7.3
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: Low
  • User Interaction: Required
  • Consequences: Gain Privileges
Vulnerabilities

CVE-2023-40352

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

McAfee Security Advisory

References