PT-2021-19541 · Mcafee · Mcafee Agent For Windows

Published

2021-06-10

·

Updated

2023-11-15

·

CVE-2021-31839

CVSS v3.1

4.8

Medium

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions McAfee Agent for Windows versions prior to 5.7.3
Description The issue is related to improper privilege management, allowing a local user to modify event information in the MA event folder. This enables the user to add false events or remove events from the event logs before they are sent to the ePO server.
Recommendations For versions prior to 5.7.3, update to version 5.7.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the MA event folder to prevent unauthorized modifications until a patch is applied.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-31839

Affected Products

Mcafee Agent For Windows