Unquoted service executable path in DXL Broker in McAfee Data eXchange Layer (DXL) Framework 6.0.0 and earlier allows local users to cause a denial of service and malicious file execution via carefully crafted and named executable files.
2020-02-17T07:15:16.537
2024-11-21T05:36:55.853
Modified
CVSSv3.1: 4.2 (MEDIUM)
AV:L/AC:M/Au:N/C:N/I:N/A:P
3.4
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | mcafee | data_exchange_layer | ≤ 6.0.0 | Yes |
| Operating System | microsoft | windows | - | No |