McAfee Vulnerabilities and Affected Products
Explore source-attributed vulnerabilities associated with McAfee products.
Products
- Network Security Management (NSM)16 vulnerabilities
- Advanced Threat Defense (ATD)12 vulnerabilities
- McAfee Web Gateway (MWG)8 vulnerabilities
- Network Data Loss Prevention (NDLP)8 vulnerabilities
- DLP ePO extension6 vulnerabilities
- ePolicy Orchestrator (ePO)6 vulnerabilities
- McAfee Total Protection (MTP)4 vulnerabilities
- True Key4 vulnerabilities
- McAfee Agent (MA) for Linux3 vulnerabilities
- Network Data Loss Prevention3 vulnerabilities
- Application and Change Control2 vulnerabilities
- Data Loss Prevention (DLP) ePO extension2 vulnerabilities
- Data Loss Prevention Endpoint (DLPe)2 vulnerabilities
- Data Loss Prevention(DLP)2 vulnerabilities
- ePolicy Orchistrator (ePO)2 vulnerabilities
- Live Safe2 vulnerabilities
- True Key (TK)2 vulnerabilities
- antivirus_vpn_for_android1 vulnerability
- Client Proxy (MCP)1 vulnerability
- Common UI (CUI)1 vulnerability
- Data Loss Prevention1 vulnerability
- Data Loss Prevention (DLP) Endpoint1 vulnerability
- Data Loss Prevention (DLP) for Windows1 vulnerability
- Database Security1 vulnerability
- Drive Encryption (MDE)1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-49592MEDIUM | Trial installer for McAfee Total Protection (legacy trial installer software) 16.0.53 allows local privilege escalation because of an Uncontrolled Search Path Element. The attacker could be "an adversary or knowledgeable user" and the type of attack could be called "DLL-squatting." The issue only affects execution of this installer, and does not leave McAfee Total Protection in a vulnerable state after installation is completed. NOTE: This vulnerability only affects products that are no longer s… CWE-427Nov 15, 2024 | CVSS6.7v3.1 | EPSS0.205% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-34405CRITICAL | Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app. CWE-94Jun 11, 2024 | CVSS9.1v3.1 | EPSS0.472% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0280HIGH | McAfee Total Protection (MTP) - File Deletion vulnerabilityA race condition vulnerability exists in the QuickClean feature of McAfee Total Protection for Windows prior to 16.0.43 that allows a local user to gain privilege elevation and perform an arbitrary file delete. This could lead to sensitive files being deleted and potentially cause denial of service. This attack exploits the way symlinks are created and how the product works with them. CWE-367Mar 10, 2022 | CVSS7.5v3.1 | EPSS0.337% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-0815MEDIUM | McAfee WebAdvisor - Extension Fingerprinting vulnerabilityImproper access control vulnerability in McAfee WebAdvisor Chrome and Edge browser extensions up to 8.1.0.1895 allows a remote attacker to gain access to McAfee WebAdvisor settings and other details about the user’s system. This could lead to unexpected behaviors including; settings being changed, fingerprinting of the system leading to targeted scams, and not triggering the malicious software if McAfee software is detected. | CVSS6.5v3.1 | EPSS0.998% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-31848HIGH | Data Loss Prevention (DLP) ePO extension - Cross site scripting (XSS)Cross site scripting (XSS) vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker to highjack an active DLP ePO administrator session by convincing the logged in administrator to click on a carefully crafted link in the case management part of the DLP ePO extension. CWE-79Nov 1, 2021 | CVSS8.4v3.1 | EPSS0.786% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-31849HIGH | Data Loss Prevention (DLP) ePO extension - SQL injectionSQL injection vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.7.100 allows a remote attacker logged into ePO as an administrator to inject arbitrary SQL into the ePO database through the user management section of the DLP ePO extension. CWE-89Nov 1, 2021 | CVSS8.4v3.1 | EPSS1.04% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-23877MEDIUM | McAfee Total Protection (MTP) - Privilege Escalation vulnerabilityPrivilege escalation vulnerability in the Windows trial installer of McAfee Total Protection (MTP) prior to 16.0.34_x may allow a local user to run arbitrary code as the admin user by replacing a specific temporary file created during the installation of the trial version of MTP. CWE-269Oct 26, 2021 | CVSS6.7v3.1 | EPSS0.358% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-23874HIGH | McAfee Total Protection (MTP) privilege escalation vulnerabilityArbitrary Process Execution vulnerability in McAfee Total Protection (MTP) prior to 16.0.30 allows a local user to gain elevated privileges and execute arbitrary code bypassing MTP self-defense. | CVSS8.2v3.1 | EPSS1.03% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7336MEDIUM | Network Security Management (NSM) - Cross Site Request Forgery vulnerabilityCross Site Request Forgery vulnerability in McAfee Network Security Management (NSM) prior to 10.1.7.35 and NSM 9.x prior to 9.2.9.55 may allow an attacker to change the configuration of the Network Security Manager via a carefully crafted HTTP request. CWE-352Jan 5, 2021 | CVSS6.6v3.1 | EPSS0.523% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7339MEDIUM | Database Security(DBS)-Use of a Broken or Risky Cryptographic AlgorithmUse of a Broken or Risky Cryptographic Algorithm vulnerability in McAfee Database Security Server and Sensor prior to 4.8.0 in the form of a SHA1 signed certificate that would allow an attacker on the same local network to potentially intercept communication between the Server and Sensors. CWE-327Dec 9, 2020 | CVSS6.3v3.1 | EPSS0.172% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7317MEDIUM | ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerabilityCross-Site Scripting vulnerability in McAfee ePolicy Orchistrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via parameter values for "syncPointList" not being correctly sanitsed. CWE-79Oct 14, 2020 | CVSS4.6v3.1 | EPSS0.339% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7318MEDIUM | ePolicy Orchistrator (ePO) - Cross-Site Scripting vulnerabilityCross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) prior to 5.10.9 Update 9 allows administrators to inject arbitrary web script or HTML via multiple parameters where the administrator's entries were not correctly sanitized. | CVSS4.6v3.1 | EPSS1.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-7316MEDIUM | File and Removable Media Protection update fixes one vulnerabilityUnquoted service path vulnerability in McAfee File and Removable Media Protection (FRP) prior to 5.3.0 allows local users to execute arbitrary code, with higher privileges, via execution and from a compromised folder. This issue may result in files not being encrypted when a policy is triggered. CWE-428Oct 7, 2020 | CVSS6.6v3.1 | EPSS0.385% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7268MEDIUM | McAfee Email Gateway (MEG) - Path Traversal vulnerabilityPath Traversal vulnerability in McAfee McAfee Email Gateway (MEG) prior to 7.6.406 allows remote attackers to traverse the file system to access files or directories that are outside of the restricted directory via external input to construct a path name that should be within a restricted directory. CWE-22Sep 16, 2020 | CVSS4.3v3.1 | EPSS0.979% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7297MEDIUM | Web Gateway (MWG) - Privilege Escalation vulnerabilityPrivilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected dashboard data via improper access control in the user interface. CWE-287Sep 15, 2020 | CVSS5.7v3.1 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7296MEDIUM | Web Gateway (MWG) - Privilege Escalation vulnerabilityPrivilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to access protected configuration files via improper access control in the user interface. CWE-287Sep 15, 2020 | CVSS5.7v3.1 | EPSS0.432% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Web Gateway (MWG) - Privilege Escalation vulnerabilityPrivilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected log data via improper access controls in the user interface. CWE-287Sep 15, 2020 | CVSS3.5v3.1 | EPSS0.464% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2020-7294MEDIUM | Web Gateway (MWG) - Privilege Escalation vulnerabilityPrivilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user to delete or download protected files via improper access controls in the REST interface. CWE-287Sep 15, 2020 | CVSS4.6v3.1 | EPSS0.389% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7293CRITICAL | Web Gateway (MWG) - Privilege Escalation vulnerabilityPrivilege Escalation vulnerability in McAfee Web Gateway (MWG) prior to 9.2.1 allows authenticated user interface user with low permissions to change the system's root password via improper access controls in the user interface. CWE-287Sep 15, 2020 | CVSS9.0v3.1 | EPSS0.66% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7307MEDIUM | DLP for Mac - Unprotected Storage of CredentialsUnprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the RiskDB username and password via unprotected log files containing plain text credentials. CWE-522Aug 13, 2020 | CVSS5.2v3.1 | EPSS0.261% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7306MEDIUM | DLP for Mac - Unprotected Storage of CredentialsUnprotected Storage of Credentials vulnerability in McAfee Data Loss Prevention (DLP) for Mac prior to 11.5.2 allows local users to gain access to the ADRMS username and password via unprotected log files containing plain text CWE-522Aug 13, 2020 | CVSS5.2v3.1 | EPSS0.248% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7305MEDIUM | DLP ePO extension - Privilege escalationPrivilege escalation vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows a low privileged remote attacker to create new rule sets via incorrect validation of user credentials. CWE-269Aug 13, 2020 | CVSS6.7v3.1 | EPSS1.02% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7304HIGH | DLP ePO extension - Cross-site request forgeryCross site request forgery vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote attacker to embed a CRSF script via adding a new label. CWE-352Aug 13, 2020 | CVSS7.6v3.1 | EPSS0.487% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7303MEDIUM | DLP ePO extension - Cross-site scriptingCross Site scripting vulnerability in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated remote user to trigger scripts to run in a user's browser via adding a new label. CWE-79Aug 13, 2020 | CVSS4.1v3.1 | EPSS0.436% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-7302MEDIUM | DLP ePO extension - Unrestricted Upload of File with Dangerous TypeUnrestricted Upload of File with Dangerous Type in McAfee Data Loss Prevention (DLP) ePO extension prior to 11.5.3 allows authenticated attackers to upload malicious files to the DLP case management section via lack of sanity checking. CWE-434Aug 13, 2020 | CVSS5.4v3.1 | EPSS0.697% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |