Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
2022-08-30T08:15:07.453
2024-11-21T07:00:46.970
Modified
CVSSv3.1: 6.5 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | mcafee | data_loss_prevention_endpoint | < 11.6.600.212 | Yes |
Application | mcafee | data_loss_prevention_endpoint | < 11.9.100 | Yes |
Operating System | microsoft | windows | - | No |