Vulnerabilidades em McAfee, LLC

59 resultados
Análise Vexday

Com 56 CVEs catalogadas e nenhuma registrada em exploração ativa no CISA KEV, o perfil de risco dos produtos McAfee se situa abaixo da média geral do catálogo, o que indica menor pressão imediata de remediação em comparação com outros fornecedores. A falha mais prevalente por tipo é CWE-264 (controle inadequado de permissões e privilégios), padrão que historicamente facilita escalonamento de privilégios local e merece atenção em ambientes onde o princípio do menor privilégio não está rigorosamente aplicado. A CVE mais relevante no momento, CVE-2018-6703, apresenta EPSS de 0,0323, sinalizando probabilidade de exploração relativamente baixa, embora sua antiguidade sugira que ambientes sem atualizações consistentes ainda possam estar expostos. A ausência de PoCs públicas conhecidas e de novas vulnerabilidades nos últimos 90 dias reforça um cenário de risco residual moderado, mais relacionado à manutenção de patches históricos do que a ameaças emergentes.

CVE-2018-6687MEDIUMGetSusp (a free McAfee tool) update fixes an infinite loop vulnerability (CVE-2018-6687)EPSS 0.8%CVE-2019-3586HIGHMcAfee Endpoint Security firewall not always acting on GTI lookup resultsEPSS 0.8%CVE-2020-7262MEDIUMImproper Access Control vulnerability in ATDEPSS 0.7%CVE-2019-3595LOWDLP Endpoint ePO extension not sanitizing CSV exportsEPSS 0.7%CVE-2019-3602MEDIUMCross site scripting vulnerability in McAfee NSM impacting authenticated usersEPSS 0.6%CVE-2020-7332HIGHCross-Site Request Forgery (CSRF) in firewall ePO extension of McAfee Endpoint Security (ENS)EPSS 0.6%CVE-2020-7333MEDIUMCross-site Scripting (XSS) in firewall ePO extension of McAfee Endpoint Security (ENS)EPSS 0.5%CVE-2020-7252MEDIUMUnquoted service executable pathEPSS 0.5%CVE-2019-3604MEDIUMePolicy Orchestrator Cloud update fixes multiple Cross-Site Request Forgery vulnerabilitiesEPSS 0.4%CVE-2020-7331HIGHUnquoted service executable path in McAfee Endpoint Security (ENS)EPSS 0.4%CVE-2020-7260HIGHMACC installer DLL side loadingEPSS 0.4%CVE-2020-7337MEDIUMIncorrect Permission Assignment for Critical ResourceEPSS 0.4%CVE-2020-7279MEDIUMDLL search order hijacking in Host IPSEPSS 0.4%CVE-2020-7280HIGHSymbolic Link vulnerability during DAT updateEPSS 0.4%CVE-2019-3582HIGHMcAfee Endpoint Security updates fix a privilege escalation vulnerabilityEPSS 0.4%CVE-2020-7309LOWCross Site Scripting vulnerability in ePO extension of MACCEPSS 0.4%CVE-2019-3613MEDIUMDLL search order hijacking in MAEPSS 0.4%CVE-2020-7343MEDIUMImproper Authorization vulnerability in MAEPSS 0.4%CVE-2019-3621MEDIUMDLP Endpoint Windows lock screen bypass with physical accessEPSS 0.3%CVE-2019-3593HIGHExploitation of Privilege/Trust vulnerabilityEPSS 0.3%