VYPR
Unrated severityNVD Advisory· Published Feb 10, 2021· Updated Aug 3, 2024

McAfee Total Protection (MTP) privilege escalation vulnerability

CVE-2021-23873

Description

Local privilege escalation in McAfee Total Protection before 16.0.30 allows arbitrary file deletion as SYSTEM via a directory junction attack.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Local privilege escalation in McAfee Total Protection before 16.0.30 allows arbitrary file deletion as SYSTEM via a directory junction attack.

Vulnerability

A privilege escalation vulnerability exists in McAfee Total Protection (MTP) prior to version 16.0.30. The flaw resides in the implementation of the QuickClean feature. By creating a directory junction, an attacker can abuse QuickClean to delete arbitrary files as the SYSTEM user, potentially causing a denial-of-service condition [1]. The attack requires low-privileged code execution on the target system.

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system. The attacker then manipulates a junction link at a specific time after enumerating certain files to trigger the vulnerability. The specific flaw allows the QuickClean feature to follow the junction to a target file or location, causing deletion of that file under the SYSTEM account context [1].

Impact

Successful exploitation allows a local attacker to delete arbitrary files as the SYSTEM user. This can lead to a denial-of-service condition on the system, potentially rendering the system unstable or unusable. The vulnerability does not directly allow information disclosure or remote code execution, but the file deletion impact is severe [1].

Mitigation

McAfee has released version 16.0.30 of Total Protection to address this vulnerability. Users should update to the latest version. No workarounds are documented. The vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog [1].

References
  1. ZDI-21-175

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

2

News mentions

0

No linked articles in our index yet.