CVE-2019-3595
DLP Endpoint ePO extension not sanitizing CSV exports
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
La neutralización inadecuada de elementos especiales utilizados en un comando ('Command Injection') en la extensión ePO en McAfee Data Loss Prevention (DLP) 11.x antes de la versión 11.3.0 permite al administrador autenticado ejecutar código arbitrario con sus privilegios de máquina local a través de una Política de DLP especialmente diseñada, que es exportada y abierta en su máquina. En nuestras verificaciones, el usuario debe permitir explícitamente que se ejecute el código.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-07-24 CVE Published
- 2024-08-04 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/109377 | Vdb Entry | |
https://kc.mcafee.com/corporate/index?page=content&id=SB10289 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Data Loss Prevention Endpoint Search vendor "Mcafee" for product "Data Loss Prevention Endpoint" | >= 11.0 < 11.1.200 Search vendor "Mcafee" for product "Data Loss Prevention Endpoint" and version " >= 11.0 < 11.1.200" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Data Loss Prevention Endpoint Search vendor "Mcafee" for product "Data Loss Prevention Endpoint" | >= 11.2.000 < 11.3.0 Search vendor "Mcafee" for product "Data Loss Prevention Endpoint" and version " >= 11.2.000 < 11.3.0" | - |
Affected
|