XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.
2021-09-17T14:15:08.097
2024-11-21T06:06:20.300
Modified
CVSSv3.1: 5.0 (MEDIUM)
AV:L/AC:L/Au:N/C:N/I:N/A:P
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | endpoint_security | < 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |
Application | mcafee | endpoint_security | 10.7.0 | Yes |