← Vulnerability feed

Vulnerability record · CVE-2021-23891 · published 12 May 2021

CVE-2021-23891: Mcafee total protection improper privilege management vulnerability

MMcafee · Total Protection

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.

7.8 CVSS 3.1 High EPSS 0.34% · top 74.9% CWE-269 · Improper privilege management
7.8CVSS 3.1 base score, v2 4.6
0.34%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Privilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating a client token which could lead to the bypassing of MTP self-defense.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-23891 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-23874McAfee Total Protection local privilege escalation via self-defense bypassMcAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism a…KEVEPSS 1.0%analysed8.8CVE-2020-7330Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call maliciou…EPSS 0.27%8.8CVE-2020-7283Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link man…EPSS 0.62%8.4CVE-2020-7298Mcafee total protection vulnerabilityUnexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially cr…EPSS 0.29%8.2CVE-2019-3617Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect…EPSS 0.32%7.8CVE-2022-43751Mcafee total protection uncontrolled search path element vulnerabilityMcAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to …EPSS 0.23%7.8CVE-2021-23877Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run a…EPSS 0.37%7.8CVE-2021-23872Mcafee total protection link following vulnerabilityPrivilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated …EPSS 0.43%

Source: NIST National Vulnerability Database (record CVE-2021-23891), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.