PT-2022-15920 · Unknown · Dlp Endpoint For Windows

Published

2022-08-30

·

Updated

2023-11-15

·

CVE-2022-2330

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DLP Endpoint for Windows versions prior to 11.9.100 DLP Endpoint for Windows version 11.6.600
Description The issue is related to an Improper Restriction of XML External Entity Reference, allowing a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
Recommendations For versions prior to 11.9.100, update to version 11.9.100 or later. For version 11.6.600, update to version 11.9.100 or later. As a temporary workaround, consider restricting access to the DLP Agent to minimize the risk of exploitation.

Fix

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-2330

Affected Products

Dlp Endpoint For Windows