QID 376433

Date Published: 2022-03-01

QID 376433: McAfee Agent Multiple Vulnerabilities (SB10378)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.

McAfee Agent is affected with the following vulnerability:
CVE-2021-31854: A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file
CVE-2022-0166: A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5 affecting all supported operating systems..
Affected versions:
McAfee Agent Prior to 5.7.5
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit and /opt/McAfee/agent/bin/msaconfig in Linux to detect the version.

Successful exploitation of this vulnerability may result command injection and privilege escalation.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Critical - 9.3 severity.
  • Solution
    Install or update to McAfee Agent 5.7.5 For more details refer SB10378

    CVEs related to QID 376433

    Software Advisories
    Advisory ID Software Component Link
    SB10378 URL Logo kc.mcafee.com/corporate/index?page=content&id=SB10378