PT-2021-19547 · Mcafee · Mcafee Data Loss Prevention (Dlp) Discover
Published
2021-09-17
·
Updated
2023-11-15
·
CVE-2021-31845
CVSS v3.1
8.4
High
| Vector | AV:A/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
McAfee Data Loss Prevention (DLP) Discover versions prior to 11.6.100
Description:
A buffer overflow issue allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.
Recommendations:
For versions prior to 11.6.100, update to version 11.6.100 or later to resolve the issue. As a temporary workaround, consider restricting access to the DLP Discover service until a patch is applied, and avoid scanning potentially malicious Ami Pro (.sam) files.
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Data Loss Prevention (Dlp) Discover