SB2018051120 - Security restrictions bypass in McAfee Data Loss Prevention Endpoint
Published: May 11, 2018
Security Bulletin ID
SB2018051120
Severity
Low
Patch available
YES
Number of vulnerabilities
1
Exploitation vector
Local access
Highest impact
Data manipulation
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Missing authorization (CVE-ID: CVE-2018-6664)
The vulnerability allows a local attacker to bypass security restrictions on the target system.The weakness exists due to missing authorization. A local attacker can generate a Master Response String on the target endpoint system to cause the DLP Endpoint protection mode to switch to bypass mode without authorization from McAfee ePolicy Orchestrator.
Remediation
Install update from vendor's website.