QID 375914

Date Published: 2021-10-04

QID 375914: McAfee Agent Multiple Vulnerabilities (SB10369)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator (McAfee ePO).
It downloads and enforces policies, and executes client-side tasks such as deployment and updating. McAfee Agent is affected with the following vulnerability:
CVE-2021-31847:Improper Verification of Cryptographic Signature.
CVE-2021-31841:Untrusted Search Path.
CVE-2021-31836:Improper Privilege Management .

Affected Software:
McAfee Agent: Prior to 5.7.4

Detection Logic:
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.

Successful exploitation allows local users to to gain access to sensitive information.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 6.9 severity.
  • Solution
    Install or update to McAfee Agent 5.7.4 For more details refer SB10369

    CVEs related to QID 375914

    Software Advisories
    Advisory ID Software Component Link
    SB10369 URL Logo kc.mcafee.com/corporate/index?page=content&id=SB10369