PT-2018-3690 · Mcafee · Mcafee Agent
CVE-2018-6706
·
Publicado
2018-12-11
·
Atualizado
2023-01-27
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee Agent versions 5.0.0 through 5.0.6
McAfee Agent versions 5.5.0 and 5.5.1
Description
The issue is related to insecure handling of temporary files in the McAfee Agent, which can be exploited by an unprivileged user to introduce custom paths during agent installation in Linux. This can potentially allow a remote attacker to elevate their privileges.
Recommendations
For McAfee Agent versions 5.0.0 through 5.0.6, update to a version outside of this range to resolve the issue.
For McAfee Agent versions 5.5.0 and 5.5.1, update to a version outside of this range to resolve the issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Mcafee Agent