Vulnerability record · CVE-2021-23874 · published 10 February 2021
CVE-2021-23874: McAfee Total Protection local privilege escalation via self-defense bypass
MMcafee · Total Protection
McAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism and execute arbitrary code with elevated privileges. Because the flaw defeats the protection the product is meant to enforce, it undermines the security posture of the host it is installed on.
Description
Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives local privilege escalation and is in CISA KEV, but it requires existing local access and the EPSS score is low.
What it is
McAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism and execute arbitrary code with elevated privileges. Because the flaw defeats the protection the product is meant to enforce, it undermines the security posture of the host it is installed on.
Impact
An attacker with local access gains elevated privileges and can run arbitrary code on the affected machine, effectively taking control of the endpoint and disabling the protections MTP provides.
Attack surface
The attack is local only (AV:L) and requires the attacker to already have low-privileged access on the host (PR:L); no user interaction is needed (UI:N). It is not remotely reachable.
Exploitation
CVE-2021-23874 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-17 remediation due date, indicating exploitation in the wild, though EPSS is low (0.01026, 61.9th percentile) and no ransomware campaign use is recorded.
What to do
- Upgrade McAfee Total Protection to 16.0.30 or later, per the vendor advisory referenced by CISA.
- Restrict interactive logon and local user accounts on endpoints running MTP to reduce the pool of low-privileged users who can trigger the flaw.
- Monitor and alert on unexpected privilege escalation or self-defense tampering events on MTP-managed hosts.
- Verify MTP self-defense and tamper protection are enabled and healthy after patching, since the flaw targets that mechanism.
Detection
- Hunt for processes spawning from or tampering with MTP components that then run with elevated privileges.
- Alert on MTP self-defense disablement or service-stop events followed by unusual child process creation.
- Correlate local user activity with privilege escalation events (for example token or integrity-level changes) on MTP endpoints.
- Check endpoint inventory for MTP versions below 16.0.30 and flag them for remediation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-23874 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "McAfee Total Protection (MTP) Improper Privilege Management Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://service.mcafee.com/FAQDocument.aspx?&id=TS103114 | Broken Link |
| http://service.mcafee.com/FAQDocument.aspx?&id=TS103114 | Broken Link |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-23874 | US Government Resource |
Track CVE-2021-23874 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-23874), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.