CVE-2021-23887
HIGHMcAfee Data Loss Prevention Endpoint < 11.6.100.41 - Privilege Escalation via hdlphook Driver Memory Manipulation
Title source: llmDescription
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.
References (2)
Core 2
Core References
Broken Link x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10354
Broken Link x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10357
Scores
CVSS v3
7.8
EPSS
0.0003
EPSS Percentile
10.6%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (1)
mcafee/data_loss_prevention_endpoint
< 11.6.100.41
Published
Apr 15, 2021
Tracked Since
Feb 18, 2026