QID 374349
QID 374349: McAfee Web Gateway Privilege Escalation Vulnerability (KB93377)
McAfee Web Gateway Anti-Malware Engine, part of McAfee Web Protection, is a powerful in-line technology designed to protect against contemporary threats delivered via HTTP and HTTPS channels, taking web exploit detection, zero-day, and targeted threat prevention to the next level.
The Netlogon service allowed a vulnerable Netlogon secure channel connection.
Affected Versions:
McAfee Web Gateway (MWG) 10.0.x, 9.x, 8.x, 7.x
QID Detection Logic :
This QID retrieves McAfee Web Gateway version and checks to see if it's vulnerable.
A successful exploit can lead to escalation of privileges.
Solution
The MWG 8.2.15 and 9.2.6 update releases address this threat. Fixed releases for 10.0.x and 7.8.2.x will follow shortly. Please visit advisory for more details.
Workaround:
The vendor has released workarounds.
Vendor References
CVEs related to QID 374349
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| KB93377 |
|