QID 375636
Date Published: 2021-06-21
QID 375636: McAfee Agent Multiple Vulnerabilities (SB10362)
The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator (McAfee ePO).
It downloads and enforces policies, and executes client-side tasks such as deployment and updating.
McAfee Agent is affected with following vulnerability:
CVE-2021-31839 : Improper Privilege Management
CVE-2021-31840 : Uncontrolled search path element
Affected Software:
McAfee Agent:
5.x prior to 5.7.3
Detection Logic:
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.
Successful exploitation allows a local user to modify event information in the MA event folder or allow an authenticated, local attacker to perform a DLL preloading attack with unsigned DLLs.
CVEs related to QID 375636
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SB10362 |
|