16 results (0.003 seconds)

CVSS: 6.8EPSS: 0%CPEs: 3EXPL: 0

30 Aug 2022 — Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly. La vulnerabilidad de restricción inadecuada de la referencia a entidades externas XML en DLP Endpoint para Windows anterior a la versión 11.9.100 permite a un atacante remoto hacer que el age... • https://kcm.trellix.com/corporate/index?page=content&id=SB10386 • CWE-611: Improper Restriction of XML External Entity Reference •

CVSS: 8.2EPSS: 0%CPEs: 2EXPL: 0

17 Sep 2021 — A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size. Una vulnerabilidad de desbordamiento del búfer en McAfee Data Loss Prevent... • https://kc.mcafee.com/corporate/index?page=content&id=SB10368 • CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') •

CVSS: 7.8EPSS: 0%CPEs: 1EXPL: 0

15 Apr 2021 — Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver. Una vulnerabilidad de Escalada de Privilegios en McAfee Data Loss Prevention (DLP) Endpoint para Windows anterior a versión 11.6.100, permit... • https://kc.mcafee.com/corporate/index?page=content&id=SB10354 • CWE-269: Improper Privilege Management •

CVSS: 5.5EPSS: 0%CPEs: 1EXPL: 0

15 Apr 2021 — Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory. Una vulnerabilidad de Denegación de Servicio en McAfee Data Loss Prevention (DLP) Endpoint para Windows anterior a versión 11.6.100, permite a un atacante local, poco privilegiado, causar un BSoD al sus... • https://kc.mcafee.com/corporate/index?page=content&id=SB10354 • CWE-755: Improper Handling of Exceptional Conditions •

CVSS: 7.4EPSS: 0%CPEs: 4EXPL: 0

23 Jul 2018 — Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline. Vulnerabilidad de explotación de niveles de seguridad de control de acceso configurados incorrectamente en McAfee Data Loss Prevention (DLP) para Windows en versiones anteriores a la 10.0.505 y 11.0.405 permite que usuarios locales omitan la política DLP e... • https://kc.mcafee.com/corporate/index?page=content&id=SB10246 • CWE-276: Incorrect Default Permissions •

CVSS: 8.8EPSS: 0%CPEs: 4EXPL: 0

25 May 2018 — Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility. Vulnerabilidad de omisión de protecciones de aplicación en Microsoft Windows en McAfee Data Loss Prevention (DLP) Endpoint, en versiones anteriores a la 10.0.500, y DLP Endpoint en versiones anteriores a la 11.0.400 permite que usuarios autenticados omitan la a... • http://www.securityfocus.com/bid/104299 • CWE-347: Improper Verification of Cryptographic Signature •

CVSS: 7.8EPSS: 0%CPEs: 2EXPL: 0

14 Mar 2017 — Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get. Vulnerabilidad de control de acceso en Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 y 9.3.600 permite a usuarios autenticados con permisos de lectura-escritura-ejecución inyectar DLLs de gancho en otros procesos a través de páginas en la memoria... • https://kc.mcafee.com/corporate/index?page=content&id=SB10185 • CWE-264: Permissions, Privileges, and Access Controls •

CVSS: 5.1EPSS: 0%CPEs: 8EXPL: 2

08 Apr 2016 — The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.152... • https://www.exploit-db.com/exploits/39531 • CWE-284: Improper Access Control •

CVSS: 6.5EPSS: 0%CPEs: 1EXPL: 0

27 Mar 2015 — The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to cause a denial of service (database lock or license corruption) via unspecified vectors. La extensión ePO en McAfee Data Loss Prevention Endpoint (DLPe) anterior a 9.3 Patch 4 Hotfix 16 (9.3.416.4) permite a usuarios remotos autenticados causar una denegación de servicio (cierre de la base de datos o corrupción de licencia) a través de vectores no especificados. • http://www.securityfocus.com/bid/73399 • CWE-399: Resource Management Errors •

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 0

27 Mar 2015 — The ePO extension in McAfee Data Loss Prevention Endpoint (DLPe) before 9.3 Patch 4 Hotfix 16 (9.3.416.4) allows remote authenticated users to obtain sensitive information, modify the database, or possibly have other unspecified impact via a crafted URL. La extensión ePO en McAfee Data Loss Prevention Endpoint (DLPe) anterior a 9.3 Patch 4 Hotfix 16 (9.3.416.4) permite a usuarios remotos autenticados obtener información sensible, modificar la base de datos o posiblemente tener otro impacto no especificados ... • http://www.securityfocus.com/bid/73397 • CWE-264: Permissions, Privileges, and Access Controls •