QID 375636

Date Published: 2021-06-21

QID 375636: McAfee Agent Multiple Vulnerabilities (SB10362)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator (McAfee ePO).
It downloads and enforces policies, and executes client-side tasks such as deployment and updating. McAfee Agent is affected with following vulnerability: CVE-2021-31839 : Improper Privilege Management CVE-2021-31840 : Uncontrolled search path element

Affected Software:
McAfee Agent: 5.x prior to 5.7.3

Detection Logic:
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.

Successful exploitation allows a local user to modify event information in the MA event folder or allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Install or update to McAfee Agent 5.7.3. For more details refer SB10362

    CVEs related to QID 375636

    Software Advisories
    Advisory ID Software Component Link
    SB10362 URL Logo kc.mcafee.com/corporate/index?page=content&id=SB10362