A File Masquerade vulnerability in McAfee Total Protection (MTP) version 16.0.R21 and earlier in Windows client allowed an attacker to read the plaintext list of AV-Scan exclusion files from the Windows registry, and to possibly replace excluded files with potential malware without being detected.
References
Link | Resource |
---|---|
https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102982 | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2019-10-28 08:15
Updated : 2020-08-24 10:37
NVD link : CVE-2019-3636
Mitre link : CVE-2019-3636
JSON object : View
CWE
CWE-312
Cleartext Storage of Sensitive Information
Products Affected
mcafee
- total_protection
microsoft
- windows