Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
2019-07-24T15:15:12.180
2024-11-21T04:42:13.880
Modified
CVSSv3.1: 6.5 (MEDIUM)
AV:L/AC:M/Au:N/C:P/I:P/A:P
3.4
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mcafee | data_loss_prevention_endpoint | < 11.1.200 | Yes |
| Application | mcafee | data_loss_prevention_endpoint | < 11.3.0 | Yes |