Vulnerability at McAfee facilitated cyber attacks

VG word pixels

Virus protection McAfee Security Scan Plus

Vulnerability in virus protection: A vulnerability in McAfee Security Scan Plus made it easier for attackers to access unauthorized rights. Fortunately, the error can already be fixed.

News

VG word pixels

4th place: McAfee Total Protection
The vulnerability in McAfee’s Security Scan Plus can already be fixed.
© McAfee

Anyone who relies on a virus scanner is actually hoping for better protection against the dangers of the Internet. At the same time, software of this type can itself be a gateway for cyber attacks. For example, McAfee’s Security Scan Plus.

Like the company in a security warning reports, attackers were able to obtain unauthorized privileges via a vulnerability in the virus scanner’s rights management and thus secure access to the installation device or other connected devices. This is commonly referred to as a LOLBin attack (LOL = “Living off the Land”).

The security researcher Nasreddine Bencherchali from Nextron Systems discovered the vulnerability.

All versions prior to 4.1.262.1 are affected by the vulnerability, which runs under the designation CVE-2022-37025. The risk of the vulnerability is classified as “high” by the company.

To fix the rights management error, McAfee recommends updating Security Scan Plus to the latest version. The update usually takes place automatically when a new version is released. For those who want to be on the safe side: A manual installation of the update can be done via the official McAfee website be made. The company also offers an instruction with which the installation proceeds without any problems.

Hacker Cyber ​​Attack Malware - Security (icon image)

KB5012170

Windows 10 & 11: August security patch only after…

If you want to install the August security patch KB5012170 for Windows, you can get error code 0x800f0922. The solution according to Microsoft: a…

19.8.2022 from
Alan Friedrichs

Continue to home page

more on the subject

emotet trojan protection

company at risk

Microsoft: mail services in the focus of phishing attacks

A phishing campaign uses targeted attacks against companies that use Microsoft mail services. Outlook users must take this into account.

CPU's: 6 desktop processors in the comparison test

ÆPIC Leak and Squip

Vulnerabilities in AMD and Intel CPUs

New vulnerabilities in AMD and Intel processors: Security researchers have discovered 2 vulnerabilities in the CPUs. What you can do about it.

The Abus HomeTec Pro CFA3000 on a wooden door

security breach

BSI warns of Abus wireless door locks

Unwanted door opener: A wireless door lock from Abus can allow attackers unauthorized access to the apartment. The BSI warns of the model.

Hacker Cyber ​​Attack Malware - Security (icon image)

KB5012170

Windows 10 & 11: August security patch only after…

If you want to install the August security patch KB5012170 for Windows, you can get error code 0x800f0922. The solution according to Microsoft: a…

Doctor's assistant digitally records a patient's data at reception

Vulnerability in practice software

More than 1 million patient data ended up unprotected on the Internet

Not compliant with data protection: Patient data ended up on the Internet for unauthorized persons to view via practice software. Several 10,000 patients were affected.

Reference-www.pc-magazin.de