VendorsMcAfeeagentall versions
Vulnerabilities

McAfee Agent

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

25CVEs
CVE-2018-6703
Remote Logging functionality had a use after free vulnerability in McAfee Agent
Published 2018-12-11 · Modified
9.8EPSS 0.032
CVE-2021-31854
Code injection vulnerability in McAfee Agent
Published 2022-01-19 · Modified
9.3EPSS 0.010
CVE-2021-1257
Cisco DNA Center Cross-Site Request Forgery Vulnerability
Published 2021-01-20 · Modified
8.8EPSS 0.008
CVE-2022-1258
SQL injection vulnerability in McAfee Agent's ePO extension
Published 2022-04-14 · Modified
8.4EPSS 0.010
CVE-2021-31847
Improper privilege management in repair process of MA for Windows
Published 2021-09-22 · Modified
8.2EPSS 0.004
CVE-2022-2313
DLL high jacking in Trellix Agent
Published 2022-07-27 · Modified
8.2EPSS 0.004
CVE-2022-0166
Privilege escalation vulnerability in McAfee Agent
Published 2022-01-19 · Modified
7.8EPSS 0.029
CVE-2018-6705
McAfee Agent (MA) for Linux Privilege Escalation vulnerability
Published 2018-12-12 · Modified
7.8EPSS 0.004
CVE-2018-6704
McAfee Agent for Linux Privilege Escalation vulnerability
Published 2018-12-12 · Modified
7.8EPSS 0.004
CVE-2022-1256
Improper Privilege Management in McAfee Agent for Windows
Published 2022-04-14 · Modified
7.8EPSS 0.003
CVE-2019-3599
McAfee Agent update fixes an Information Disclosure vulnerability
Published 2019-02-28 · Modified
7.5EPSS 0.018
CVE-2018-6706
McAfee Agent (MA) non-Windows versions incorrect use of temporary file vulnerability
Published 2018-12-12 · Modified
7.5EPSS 0.006
CVE-2019-3613
DLL search order hijacking in MA
Published 2020-06-10 · Modified
7.3EPSS 0.004
CVE-2019-3592
MA for Windows update addresses weak directory permissions
Published 2019-07-18 · Modified
7.2EPSS 0.003
CVE-2018-6707
McAfee Agent Insecure usage of temporary files vulnerability
Published 2018-12-13 · Modified
7.0EPSS 0.003
CVE-2022-1257
Improper Verification of Cryptographic Signature by McAfee Agent
Published 2022-04-14 · Modified
6.11 PoCEPSS 0.006
CVE-2019-1559
0-byte record padding oracle
Published 2019-02-27 · Modified
5.9EPSS 0.171
CVE-2020-7253
Improper access control vulnerability in McAfee Agent
Published 2020-03-12 · Modified
5.7EPSS 0.002
CVE-2020-7343
Improper Authorization vulnerability in MA
Published 2021-01-18 · Modified
5.5EPSS 0.004
CVE-2008-1357
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.
Published 2008-03-17 · Modified
5.41 PoCEPSS 0.062
CVE-2019-3598
McAfee Agent update fixes a vulnerability in handling UDP requests
Published 2019-02-28 · Modified
5.3EPSS 0.019
CVE-2015-8987
Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.
Published 2017-03-14 · Modified
5.3EPSS 0.005
CVE-2016-3984
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
Published 2016-04-08 · Modified
5.11 PoCEPSS 0.011
CVE-2013-3627
FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to cause a denial of service (service crash) via a malformed HTTP request.
Published 2013-10-05 · Modified
5.0EPSS 0.020
CVE-2021-31839
Incorrect permissions on McAfee Agent for Windows event folder
Published 2021-06-10 · Modified
4.8EPSS 0.002