QID 376433
Date Published: 2022-03-01
QID 376433: McAfee Agent Multiple Vulnerabilities (SB10378)
The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.
McAfee Agent is affected with the following vulnerability:
CVE-2021-31854: A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file
CVE-2022-0166: A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5 affecting all supported operating systems..
Affected versions:
McAfee Agent Prior to 5.7.5
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit
and /opt/McAfee/agent/bin/msaconfig in Linux to detect the version.
Successful exploitation of this vulnerability may result command injection and privilege escalation.
CVEs related to QID 376433
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SB10378 |
|