CVE-2022-37025
Estado: ModificadaAlta (7.8)—
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.21%
- Percentil entre todas las CVEs puntuadas: 11
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-269
Referencias
- https://attack.mitre.org/techniques/T1218/
- https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.html
- https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-view
- https://attack.mitre.org/techniques/T1218/
- https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.html
- https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-view
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-37025",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-08-18T13:15:08.010",
"references": [
{
"url": "https://attack.mitre.org/techniques/T1218/",
"tags": [
"Not Applicable"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.html",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-view",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://attack.mitre.org/techniques/T1218/",
"tags": [
"Not Applicable"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mcafee.com/en-us/antivirus/mcafee-security-scan-plus.html",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.mcafee.com/support/?articleId=TS103335&page=shell&shell=article-view",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-269"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack. This could result in the user gaining elevated permissions and being able to execute arbitrary code due to lack of an integrity check of the configuration file."
},
{
"lang": "es",
"value": "Una vulnerabilidad de administración de privilegios inapropiada en McAfee Security Scan Plus (MSS+) versiones anteriores a 4.1.262.1 podría permitir a un usuario local modificar un archivo de configuración y llevar a cabo un ataque de tipo LOLBin (Living off the land). Esto podía resultar en que el usuario consiguiera permisos elevados y pudiera ejecutar código arbitrario debido a una falta de comprobación de la integridad del archivo de configuración."
}
],
"lastModified": "2026-06-17T04:54:29.547",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:security_scan_plus:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A9CE715F-32EF-476A-AAF5-22F3A6B936F3",
"versionEndExcluding": "4.1.262.1"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}