QID 376845

Date Published: 2022-08-22

QID 376845: McAfee Agent Execute Arbitrary Code Vulnerability (SB10385)

The McAfee Agent is the distributed component of McAfee ePolicy Orchestrator. It downloads and enforces policies, and executes client-side tasks such as deployment and updating. The Agent also uploads events and provides additional data regarding each system status.

CVE-2022-2313: Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL into the folder from where the Smart installer is being executed.
Affected versions:
McAfee Agent Prior to 5.7.7
QID Detection Logic(Authenticated):
The QID checks for vulnerable version of McAfee Agent by checking the version information at HKLM\SOFTWARE\McAfee\Agent registry key for 32/64 bit.

Successful exploitation of this vulnerability may allow an attacker to steal sensitive information from the target.

  • CVSS V3 rated as High - 7.3 severity.
  • CVSS V2 rated as Low - 2.1 severity.
  • Solution
    Install or update to McAfee Agent 5.7.7 For more details refer SB10385

    CVEs related to QID 376845

    Software Advisories
    Advisory ID Software Component Link
    SB10385 URL Logo kcm.trellix.com/corporate/index?page=content&id=SB10385