{"api_version":"1","generated_at":"2026-05-08T14:33:13+00:00","cve":"CVE-2018-6664","urls":{"html":"https://cve.report/CVE-2018-6664","api":"https://cve.report/api/cve/CVE-2018-6664.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2018-6664","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2018-6664"},"summary":{"title":"CVE-2018-6664","description":"Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.","state":"PUBLIC","assigner":"psirt@mcafee.com","published_at":"2018-05-25 13:29:00","updated_at":"2023-11-07 03:00:00"},"problem_types":["CWE-347"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/104299","name":"104299","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"McAfee Data Loss Prevention Endpoint CVE-2018-6664 Local Security Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10237","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10237","refsource":"","tags":[],"title":"McAfee Security Bulletin - VirusScan Enterprise 8.8 for Windows update fixes McTray elevation with log files vulnerability (CVE-2018-6674)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10233","name":"MISC","refsource":"MISC","tags":["Vendor Advisory"],"title":"McAfee Security Bulletin - Data Loss Prevention Endpoint update fixes master bypass vulnerability (CVE-2018-6664)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1040895","name":"1040895","refsource":"","tags":[],"title":"McAfee Data Loss Prevention Endpoint Flaw Lets Local Users Bypass Security Restrictions - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2018-6664","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2018-6664","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2018","cve_id":"6664","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention_endpoint","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6664","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"data_loss_prevention_endpoint","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6664","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2018","cve_id":"6664","vulnerable":"0","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"psirt@mcafee.com","DATE_PUBLIC":"2018-05-08T17:00:00.000Z","ID":"CVE-2018-6664","STATE":"PUBLIC","TITLE":"SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 - Application Protections Bypass vulnerability"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":" Data Loss Prevention (DLP) Endpoint","version":{"version_data":[{"affected":"<","platform":"x86","version_name":"10","version_value":"10.0.500"}]}},{"product_name":" Data Loss Prevention (DLP) Endpoint","version":{"version_data":[{"affected":"<","version_name":"11","version_value":"11.0.400"}]}}]},"vendor_name":"McAfee"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility."}]},"impact":{"cvss":{"attackComplexity":"HIGH","attackVector":"PHYSICAL","availabilityImpact":"HIGH","baseScore":5.8,"baseSeverity":"MEDIUM","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.0/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:H","version":"3.0"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Application Protection Bypass vulnerability"}]}]},"references":{"reference_data":[{"name":"104299","refsource":"BID","url":"http://www.securityfocus.com/bid/104299"},{"name":"1040895","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1040895"},{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10237","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10237"}]},"source":{"advisory":"SB10233","discovery":"EXTERNAL"}},"nvd":{"publishedDate":"2018-05-25 13:29:00","lastModifiedDate":"2023-11-07 03:00:00","problem_types":["CWE-347"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.5},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*","versionEndExcluding":"10.0.500","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]},{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*","versionEndExcluding":"11.0.400","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2018","CveId":"6664","Ordinal":"122873","Title":"CVE-2018-6664","CVE":"CVE-2018-6664","Year":"2018"},"notes":[{"CveYear":"2018","CveId":"6664","Ordinal":"1","NoteData":"Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.","Type":"Description","Title":null},{"CveYear":"2018","CveId":"6664","Ordinal":"2","NoteData":"2018-05-25","Type":"Other","Title":"Published"},{"CveYear":"2018","CveId":"6664","Ordinal":"3","NoteData":"2018-05-30","Type":"Other","Title":"Modified"}]}}}