← Vulnerability feed

Vulnerability record · CVE-2022-43751 · published 23 November 2022

CVE-2022-43751: Mcafee total protection uncontrolled search path element vulnerability

MMcafee · Total Protection

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges.

7.8 CVSS 3.1 High EPSS 0.23% · top 87.7% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score
0.23%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

McAfee Total Protection prior to version 16.0.49 contains an uncontrolled search path element vulnerability due to the use of a variable pointing to a subdirectory that may be controllable by an unprivileged user. This may have allowed the unprivileged user to execute arbitrary code with system privileges.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-43751 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-23874McAfee Total Protection local privilege escalation via self-defense bypassMcAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism a…KEVEPSS 1.0%analysed8.8CVE-2020-7330Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) trial prior to 4.0.176.1 allows local users to schedule tasks which call maliciou…EPSS 0.27%8.8CVE-2020-7283Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) before 16.0.R26 allows local users to create and edit files via symbolic link man…EPSS 0.62%8.4CVE-2020-7298Mcafee total protection vulnerabilityUnexpected behavior violation in McAfee Total Protection (MTP) prior to 16.0.R26 allows local users to turn off real time scanning via a specially cr…EPSS 0.29%8.2CVE-2019-3617Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in McAfee Total Protection (ToPS) for Mac OS prior to 4.6 allows local users to gain root privileges via incorrect…EPSS 0.32%7.8CVE-2021-23877Mcafee total protection improper privilege management vulnerabilityPrivilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run a…EPSS 0.37%7.8CVE-2021-23872Mcafee total protection link following vulnerabilityPrivilege Escalation vulnerability in the File Lock component of McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated …EPSS 0.43%7.8CVE-2021-23891Mcafee total protection improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee Total Protection (MTP) prior to 16.0.32 allows a local user to gain elevated privileges by impersonating…EPSS 0.34%

Source: NIST National Vulnerability Database (record CVE-2022-43751), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.