CVE-2019-3585
Estado: ModificadaAlta (7.8)—
Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.28%
- Percentil entre todas las CVEs puntuadas: 19
- Fecha de la puntuación: 4/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-269
- CWE-269
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2019-3585",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "trellixpsirt@trellix.com",
"affectedData": [
{
"vendor": "McAfee, LLC",
"product": "McAfee VirusScan Enterprise (VSE)",
"versions": [
{
"status": "affected",
"version": "8.8.x",
"lessThan": "8.8 Patch 14",
"versionType": "custom"
}
]
}
]
}
],
"published": "2020-06-10T12:15:11.057",
"references": [
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10302",
"source": "trellixpsirt@trellix.com"
},
{
"url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10302",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "trellixpsirt@trellix.com",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Privilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow local users to interact with the On-Access Scan Messages - Threat Alert Window with elevated privileges via running McAfee Tray with elevated privileges."
},
{
"lang": "es",
"value": "Una vulnerabilidad de Escalada de Privilegios en el cliente (McTray.exe) de Microsoft Windows en McAfee VirusScan Enterprise (VSE) versión 8.8 anterior al parche 14 puede permitir que los usuarios locales interactúen con On-Access Scan Messages - Threat Alert Window con privilegios elevados mediante la ejecución de McAfee Tray con privilegios elevados"
}
],
"lastModified": "2026-06-17T02:35:16.563",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:-:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "A0280F82-EC6B-4F5B-A495-DD9CEED6A20D"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch1:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "66F4B2B4-93EF-4BF2-A949-4EABB6E2D5CD"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch10:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "8915A4A0-A6A8-433C-9E03-2FE2023E576D"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch11:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "12630925-6631-40DB-84EF-35BFE6EFB4F7"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch12:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "8EB533F2-0631-4C2C-885A-C132EC937164"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch13:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "D17EC9A7-A383-4B3E-A292-73CD33E60134"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch2:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "1204EDA4-8C76-45D1-894A-CBD042A1C533"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch3:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "BB3F4704-7A78-4223-98A6-EAE027553732"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch4:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "D0545B55-45D8-440D-A120-F0ED7337CF06"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch5:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "3CDA7115-7071-42BC-99AA-FD01A5CB6D37"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch6:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "54AC8CF5-30D5-4FF8-83C8-70FF9E16FE00"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch7:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "5D98604B-B10B-473A-A219-BF6208779912"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch8:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "923A8D73-6FAB-4826-B6BD-6D006E46C7BE"
},
{
"criteria": "cpe:2.3:a:mcafee:virusscan_enterprise:8.8:patch9:*:*:*:windows:*:*",
"vulnerable": true,
"matchCriteriaId": "1846CE6C-EDAE-4F88-8CC3-2C48506595F7"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "trellixpsirt@trellix.com"
}