Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
mcafee agent vulnerabilities and exploits
(subscribe to this query)
6.7
CVSSv3
CVE-2019-3592
Privilege escalation vulnerability in McAfee Agent (MA) prior to 5.6.1 HF3, allows local administrator users to potentially disable some McAfee processes by manipulating the MA directory control and placing a carefully constructed file in the MA directory.
Mcafee Agent
7.3
CVSSv3
CVE-2019-3613
DLL Search Order Hijacking vulnerability in McAfee Agent (MA) before 5.6.4 allows attackers with local access to execute arbitrary code via execution from a compromised folder.
Mcafee Agent
5.5
CVSSv3
CVE-2020-7343
Missing Authorization vulnerability in McAfee Agent (MA) for Windows before 5.7.1 allows local users to block McAfee product updates by manipulating a directory used by MA for temporary files. The product would continue to function with out-of-date detection files.
Mcafee Agent
3.3
CVSSv3
CVE-2021-31839
Improper privilege management vulnerability in McAfee Agent for Windows before 5.7.3 allows a local user to modify event information in the MA event folder. This allows a local user to either add false events or remove events from the event logs prior to them being sent to the eP...
Mcafee Agent
7.8
CVSSv3
CVE-2021-31847
Improper access control vulnerability in the repair process for McAfee Agent for Windows before 5.7.4 could allow a local malicious user to perform a DLL preloading attack using unsigned DLLs. This would result in elevation of privileges and the ability to execute arbitrary code ...
Mcafee Agent
7.8
CVSSv3
CVE-2021-31854
A command Injection Vulnerability in McAfee Agent (MA) for Windows before 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature...
Mcafee Agent
7.8
CVSSv3
CVE-2022-1256
A local privilege escalation vulnerability in MA for Windows before 5.7.6 allows a local low privileged user to gain system privileges through running the repair functionality. Temporary file actions were performed on the local user's %TEMP% directory with System privileges ...
Mcafee Agent
7.2
CVSSv3
CVE-2022-1258
A blind SQL injection vulnerability in the ePolicy Orchestrator (ePO) extension of MA before 5.7.6 can be exploited by an authenticated administrator on ePO to perform arbitrary SQL queries in the back-end database, potentially leading to command execution on the server.
Mcafee Agent
7.8
CVSSv3
CVE-2022-0166
A privilege escalation vulnerability in the McAfee Agent before 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and execute...
Mcafee Agent
4.4
CVSSv3
CVE-2020-7253
Improper access control vulnerability in masvc.exe in McAfee Agent (MA) before 5.6.4 allows local users with administrator privileges to disable self-protection via a McAfee supplied command-line utility.
Mcafee Agent
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »