vulnerability
McAfee Agent: CVE-2018-6703: Mcafee agent update fixes a use after free vulnerability in the remote logging feature (SB10258)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:P/I:P/A:P) | Dec 11, 2018 | Aug 11, 2020 | Aug 11, 2020 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:P/I:P/A:P)
Published
Dec 11, 2018
Added
Aug 11, 2020
Modified
Aug 11, 2020
Description
Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.
Solution(s)
mcafee-agent-upgrade-5-0-6-586mcafee-agent-upgrade-5-5-1-462mcafee-agent-upgrade-5-6-0-702

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.