Loading HuntDB...

GHSA-946v-pv29-q7hv

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

An uncontrolled search path vulnerability in McAfee Consumer Product Removal Tool prior to version 10.4.128 could allow a local attacker to perform a sideloading attack by using a specific file name. This could result in the user gaining elevated permissions and being able to execute arbitrary code as there were insufficient checks on the executable being signed by McAfee.

Related CVEs

Key Information

GHSA ID
GHSA-946v-pv29-q7hv
Published
June 21, 2022 12:00 AM
Last Modified
June 29, 2022 12:00 AM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 2, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.