CVE-2019-3587: McAfee Total Protection

Medium severity, CVSS 6.5. EPSS: 1.4% chance of exploitation in the next 30 days.

DLL Search Order Hijacking vulnerability in Microsoft Windows client in McAfee Total Protection (MTP) Prior to 16.0.18 allows local users to execute arbitrary code via execution from a compromised folder.

Affected products

  • McAfee Total Protection: before 16.0.18 (fixed in 16.0.18)

Published 2019-01-23. Last modified 2026-06-17.