PT-2019-3998 · Mcafee · Mcafee Data Loss Prevention
Published
2019-07-23
·
Updated
2020-10-16
·
CVE-2019-3622
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
McAfee Data Loss Prevention (DLPe) for Windows versions prior to 11.3.0
Description
The issue is related to insufficient access control in McAfee Data Loss Prevention Endpoint, allowing an authenticated user to redirect log files to arbitrary locations by creating symbolic links due to incorrect access control applied to the log folder. This can be exploited by a privileged user.
Recommendations
For versions prior to 11.3.0, update to version 11.3.0 or later to resolve the issue.
As a temporary workaround, consider restricting access to the DLPe log folder to prevent privileged users from creating symbolic links until a patch is available.
Fix
Improper Access Control
Files Accessible to External Parties
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Data Loss Prevention