VYPR

Agent

by McAfee

CVEs (37)

  • CVE-2018-6703CriDec 11, 2018
    risk 0.64cvss 9.8epss 0.03

    Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging…

  • CVE-2021-1257HigJan 20, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack to manipulate an authenticated user into executing malicious actions without their awareness…

  • CVE-2022-1258HigApr 14, 2022
    risk 0.55cvss 8.4epss 0.01

    A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA prior to 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.

  • CVE-2022-2313HigJul 27, 2022
    risk 0.53cvss 8.2epss 0.00

    A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.

  • CVE-2021-31847HigSep 22, 2021
    risk 0.53cvss 8.2epss 0.00

    Improper access control vulnerability in the repair process for McAfee Agent for Windows prior to 5.7.4 could allow a local attacker to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code as…

  • CVE-2021-31841HigSep 22, 2021
    risk 0.53cvss 8.2epss 0.00

    A DLL sideloading vulnerability in McAfee Agent for Windows prior to 5.7.4 could allow a local user to perform a DLL sideloading attack with an unsigned DLL with a specific name and in a specific location. This would result in the user gaining elevated permissions and the…

  • CVE-2020-7314HigSep 10, 2020
    risk 0.53cvss 8.2epss 0.00

    Privilege Escalation Vulnerability in the installer in McAfee Data Exchange Layer (DXL) Client for Mac shipped with McAfee Agent (MA) for Mac prior to MA 5.6.6 allows local users to run commands as root via incorrectly applied permissions on temporary files.

  • CVE-2022-1256HigApr 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability in MA for Windows prior to 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges…

  • CVE-2022-0166HigJan 19, 2022
    risk 0.51cvss 7.8epss 0.03

    A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and…

  • CVE-2020-7312HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.00

    DLL Search Order Hijacking Vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code and escalate privileges via execution from a compromised folder.

  • CVE-2020-7311HigSep 10, 2020
    risk 0.51cvss 7.8epss 0.00

    Privilege Escalation vulnerability in the installer in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to assume SYSTEM rights during the installation of MA via manipulation of log files.

  • CVE-2018-6705HigDec 12, 2018
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.

  • CVE-2018-6704HigDec 12, 2018
    risk 0.51cvss 7.8epss 0.00

    Privilege escalation vulnerability in McAfee Agent (MA) for Linux 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows local users to perform arbitrary command execution via specific conditions.

  • CVE-2021-31854HigJan 19, 2022
    risk 0.50cvss 7.7epss 0.01

    A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment…

  • CVE-2019-3599HigFeb 28, 2019
    risk 0.49cvss 7.5epss 0.02

    Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information via remote logging when it is enabled.

  • CVE-2018-6706HigDec 12, 2018
    risk 0.49cvss 7.5epss 0.01

    Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.

  • CVE-2021-31840HigJun 10, 2021
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the preloading mechanism of specific dynamic link libraries in McAfee Agent for Windows prior to 5.7.3 could allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs. To exploit this vulnerability, the attacker would need to…

  • CVE-2019-3592HigJul 18, 2019
    risk 0.47cvss 7.2epss 0.00

    Privilege escalation vulnerability in McAfee Agent (MA) before 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.

  • CVE-2022-1257MedApr 14, 2022
    risk 0.43cvss 6.1epss 0.01

    Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

  • CVE-2020-7315MedSep 10, 2020
    risk 0.39cvss 6.0epss 0.00

    DLL Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.6.6 allows local users to execute arbitrary code via careful placement of a malicious DLL.

Page 1 of 2