VYPR
Critical severity9.8NVD Advisory· Published Dec 11, 2018· Updated Jun 17, 2026

CVE-2018-6703

CVE-2018-6703

Description

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.

Affected products

3
  • McAfee/Agent2 versions
    cpe:2.3:a:mcafee:agent:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:mcafee:agent:*:*:*:*:*:*:*:*range: >=5.0.0,<5.6.0
    • (no CPE)range: <5.6.0
  • McAfee, LLC/McAfee Agentv5
    Range: 5.x

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.