← Vulnerability feed

Vulnerability record · CVE-2021-23874 · published 10 February 2021

CVE-2021-23874: McAfee Total Protection local privilege escalation via self-defense bypass

MMcafee · Total Protection

McAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism and execute arbitrary code with elevated privileges. Because the flaw defeats the protection the product is meant to enforce, it undermines the security posture of the host it is installed on.

7.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 1.0% · top 37.8% CWE-269 · Improper privilege managementCWE-732 · Incorrect permission assignment
7.8CVSS 3.1 base score, v2 4.6
1.0%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Arbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: medium.

high priorityThe flaw gives local privilege escalation and is in CISA KEV, but it requires existing local access and the EPSS score is low.

What it is

McAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism and execute arbitrary code with elevated privileges. Because the flaw defeats the protection the product is meant to enforce, it undermines the security posture of the host it is installed on.

Impact

An attacker with local access gains elevated privileges and can run arbitrary code on the affected machine, effectively taking control of the endpoint and disabling the protections MTP provides.

Attack surface

The attack is local only (AV:L) and requires the attacker to already have low-privileged access on the host (PR:L); no user interaction is needed (UI:N). It is not remotely reachable.

Exploitation

CVE-2021-23874 is listed in CISA's Known Exploited Vulnerabilities catalog with a 2021-11-17 remediation due date, indicating exploitation in the wild, though EPSS is low (0.01026, 61.9th percentile) and no ransomware campaign use is recorded.

What to do

  • Upgrade McAfee Total Protection to 16.0.30 or later, per the vendor advisory referenced by CISA.
  • Restrict interactive logon and local user accounts on endpoints running MTP to reduce the pool of low-privileged users who can trigger the flaw.
  • Monitor and alert on unexpected privilege escalation or self-defense tampering events on MTP-managed hosts.
  • Verify MTP self-defense and tamper protection are enabled and healthy after patching, since the flaw targets that mechanism.

Detection

  • Hunt for processes spawning from or tampering with MTP components that then run with elevated privileges.
  • Alert on MTP self-defense disablement or service-stop events followed by unusual child process creation.
  • Correlate local user activity with privilege escalation events (for example token or integrity-level changes) on MTP endpoints.
  • Check endpoint inventory for MTP versions below 16.0.30 and flag them for remediation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-23874 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "McAfee Total Protection (MTP) Improper Privilege Management Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23874 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2020-7330Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call maliciou…EPSS 0.27%8.8CVE-2020-7283Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link man…EPSS 0.62%8.4CVE-2020-7298Mcafee total protection vulnerabilityUnexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially cr…EPSS 0.29%8.2CVE-2019-3617Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect…EPSS 0.32%7.8CVE-2022-43751Mcafee total protection uncontrolled search path element vulnerabilityMcAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to …EPSS 0.23%7.8CVE-2021-23877Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run a…EPSS 0.37%7.8CVE-2021-23872Mcafee total protection link following vulnerabilityPrivilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated …EPSS 0.43%7.8CVE-2021-23891Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2021-23874), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.