CVE-2021-31845
Remote Code Execution in McAfee DLP Discover
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.
Una vulnerabilidad de desbordamiento de búfer en McAfee Data Loss Prevention (DLP) Discover versiones anteriores a 11.6.100, permite a un atacante que se encuentre en la misma red que DLP Discover ejecutar código arbitrario mediante la colocación de archivos Ami Pro (.sam) cuidadosamente construidos en una máquina y haciendo que DLP Discover la analice, conllevando a una ejecución de código remota con privilegios elevados. Esto es causado porque el búfer de destino es de tamaño fijo y comprobaciones incorrectas han sido realizadas en el tamaño de origen
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-04-27 CVE Reserved
- 2021-09-17 CVE Published
- 2024-03-01 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-120: Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10368 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Data Loss Prevention Discover Search vendor "Mcafee" for product "Data Loss Prevention Discover" | < 11.6.100 Search vendor "Mcafee" for product "Data Loss Prevention Discover" and version " < 11.6.100" | - |
Affected
| ||||||
Mcafee Search vendor "Mcafee" | Data Loss Prevention Discover Search vendor "Mcafee" for product "Data Loss Prevention Discover" | >= 11.7.0 < 11.7.100 Search vendor "Mcafee" for product "Data Loss Prevention Discover" and version " >= 11.7.0 < 11.7.100" | - |
Affected
|