Aller au contenu

Fiche vulnérabilité

CVE-2021-31845 : faille élevée mcafee data loss prevention discover (CVSS 7.3)

Description

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

En bref

Sévérité
Élevée (CVSS 7.3)
Vecteur CVSS
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
17 sept. 2021
Dernière mise à jour
17 juin 2026

Produits concernés

  • mcafee data loss prevention discover

Références

Rechercher une autre vulnérabilité dans la base CVE