McAfee Data Loss Prevention Endpoint for Windows Multiple Local Security Vulnerabilities
BID:109377
CVE-2019-3591 | CVE-2019-3595 |Info
McAfee Data Loss Prevention Endpoint for Windows Multiple Local Security Vulnerabilities
| Bugtraq ID: | 109377 |
| Class: | Input Validation Error |
| CVE: |
CVE-2019-3591 CVE-2019-3595 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 24 2019 12:00AM |
| Updated: | Jul 24 2019 12:00AM |
| Credit: | Roberto Suggi Liverani at NCIA / NCIRC, and Ishita Rajiv Sailor |
| Vulnerable: |
McAfee Data Loss Prevention Endpoint 11.2 McAfee Data Loss Prevention Endpoint 11.1.100 McAfee Data Loss Prevention Endpoint 11.1 McAfee Data Loss Prevention Endpoint 11.0.700 McAfee Data Loss Prevention Endpoint 11.0.600 McAfee Data Loss Prevention Endpoint 11.0.500 McAfee Data Loss Prevention Endpoint 11.0.400 McAfee Data Loss Prevention Endpoint 11.0.300 McAfee Data Loss Prevention Endpoint 11.0.200 McAfee Data Loss Prevention Endpoint 11.0 |
| Not Vulnerable: |
McAfee Data Loss Prevention Endpoint 11.3 McAfee Data Loss Prevention Endpoint 11.1.200 |
Discussion
McAfee Data Loss Prevention Endpoint for Windows Multiple Local Security Vulnerabilities
McAfee Data Loss Prevention Endpoint for Windows is prone to the following security vulnerabilities.
1. A cross-site scripting vulnerability
2. An arbitrary code-execution vulnerability
An attacker may leverage these issues to execute arbitrary script code in the 'ePolicy Orchestrator' user interface of an unsuspecting user in the context of the affected application and steal cookie-based authentication credentials or execute arbitrary code within the context of the vulnerable application.
McAfee Data Loss Prevention Endpoint 11.x versions prior to 11.3.0 are vulnerable.
McAfee Data Loss Prevention Endpoint for Windows is prone to the following security vulnerabilities.
1. A cross-site scripting vulnerability
2. An arbitrary code-execution vulnerability
An attacker may leverage these issues to execute arbitrary script code in the 'ePolicy Orchestrator' user interface of an unsuspecting user in the context of the affected application and steal cookie-based authentication credentials or execute arbitrary code within the context of the vulnerable application.
McAfee Data Loss Prevention Endpoint 11.x versions prior to 11.3.0 are vulnerable.
Exploit / POC
McAfee Data Loss Prevention Endpoint for Windows Multiple Local Security Vulnerabilities
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
McAfee Data Loss Prevention Endpoint for Windows Multiple Local Security Vulnerabilities
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.