CVE-2022-1257

MEDIUM

MA <5.7.6 - Info Disclosure

Title source: llm

Description

Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.

Exploits (2)

nomisec WORKING POC
by kayes817 · poc
https://github.com/kayes817/CVE-2022-1257
exploitdb WORKING POC
by Keenan Scott · textremotemultiple
https://www.exploit-db.com/exploits/52345

Scores

CVSS v3 6.1
EPSS 0.0018
EPSS Percentile 39.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N

Classification

CWE
CWE-922
Status published

Affected Products (1)

mcafee/agent < 5.7.6

Timeline

Published Apr 14, 2022
Tracked Since Feb 18, 2026