True Key Browser Extension 3.1.9219.0 update fixes Sensitive Data Exposure vulnerability
13Vexday Risk Score
No sign of exploitation. It 7 threat group(s) use it.
ssvc Trackcvss 5.6epss 0.3%
exploitation probability
0.3%top 77% of all CVEs
observed exploitation
nono source reports it
7 group(s)
Who exploits it — 7
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
APT / StateFox Kitten🇮🇷 MITRE ATT&CK
APT / StateIndrik Spider🇷🇺 MITRE ATT&CK
APT / StateLAPSUS$ MITRE ATT&CK
APT / StateScattered Spider MITRE ATT&CK
APT / StateStorm-0501 MITRE ATT&CK
APT / StateThreat Group-3390🇨🇳 MITRE ATT&CK
APT / StateUNC3886🇨🇳 MITRE ATT&CK
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware.
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Affected products
McAfee, LLC · True Key (TK)