Vulnerabilities in McAfee,LLC

82 results
Vexday analysis

O portfólio de vulnerabilidades catalogadas da McAfee, LLC soma 82 CVEs, com 3 classificadas como críticas e nenhuma nova entrada nos últimos 90 dias, o que indica um volume relativamente estável no período recente. A taxa de exploração ativa — 1 CVE confirmada no catálogo CISA KEV, representando 1,22% do total — está 2,7 vezes acima da média geral do catálogo, sinalizando uma proporção de ameaças materializadas que merece atenção. A CVE mais perigosa em exploração ativa é CVE-2021-23874, relacionada a gerenciamento inadequado de privilégios, tipo de falha que também corresponde ao CWE mais recorrente no conjunto (CWE-269), sugerindo um padrão estrutural nessa classe de fraqueza. A ausência de PoCs públicas conhecidas limita ligeiramente a superfície de exploração oportunista, mas a presença confirmada de exploração ativa exige que equipes de segurança priorizem a verificação do status de correção dessa CVE em ambientes onde produtos da McAfee ainda estejam em operação.

CVE-2022-1823HIGHMcAfee MCPR privilege escalationEPSS 0.3%CVE-2020-7287HIGHPrivilege Escalation vulnerability in EDR for LinuxEPSS 0.3%CVE-2020-7286HIGHPrivilege Escalation vulnerability in EDR for WindowsEPSS 0.3%CVE-2020-7285HIGHPrivilege Escalation vulnerability in MVISION EndpointEPSS 0.3%CVE-2020-7290HIGHPrivilege Escalation vulnerability in MAR for LinuxEPSS 0.3%CVE-2021-31833HIGHPotential product security bypass vulnerability in McAfee Application and Change Control (MACC) prior to version 8.3.4 allows a locally loggEPSS 0.3%CVE-2020-7291HIGHPrivilege Escalation vulnerability MAR for MacEPSS 0.3%CVE-2020-7288HIGHPrivilege Escalation vulnerability in EDR for MacEPSS 0.3%CVE-2022-1256HIGHImproper Privilege Management in McAfee Agent for WindowsEPSS 0.3%CVE-2020-7281HIGHPrivilege Escalation vulnerability in McAfee Total Protection (MTP)EPSS 0.2%CVE-2021-31841HIGHDLL side loading vulnerability in MA for WindowsEPSS 0.2%CVE-2021-31842MEDIUMXML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a loEPSS 0.2%CVE-2021-23887HIGHPrivilege escalation in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2021-23886MEDIUMLocal Denial of Service in McAfee DLP Endpoint for WindowsEPSS 0.2%CVE-2021-23884MEDIUMClear text exposure of password in McAfee CSR ePO extensionEPSS 0.2%CVE-2022-0859MEDIUMePO database restoration vulnerabilityEPSS 0.2%CVE-2021-23896LOWCleartext Transmission of Sensitive Information in McAfee DBSecEPSS 0.2%CVE-2021-31836MEDIUMImproper Privilege Management in MA for WindowsEPSS 0.2%CVE-2021-23892HIGHBy exploiting a time of check to time of use (TOCTOU) race condition during the Endpoint Security for Linux Threat Prevention and Firewall (EPSS 0.2%CVE-2021-31853HIGHMDE DLL Search Order Hijacking vulnerabilityEPSS 0.2%