QID 376619
Date Published: 2022-05-25
QID 376619: McAfee Agent Multiple Insecure Storage Vulnerability (SB10382)
The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.
CVE-2022-1257: Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db.
Affected versions:
McAfee Agent Prior to 5.7.6
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit and /opt/McAfee/agent/bin/msaconfig in Linux to detect the version.
Successful exploitation of this vulnerability may allow an attacker to steal sensitive information from the target.
CVEs related to QID 376619
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SB10382 |
|