McAfee issues security bulletin, patches bugs that can lead to system level privileges

In brief: McAfee Agent, a component of the company’s ePolicy Orchestrator (ePO), is deployed to client machines to report data, status, and enforce policies. Earlier this week, the company released a security bulletin highlighting two CVEs affecting previous versions of the ePO Agent deployed to support ePO efforts. The company released an updated version of the Agent that effectively remediates the vulnerabilities, both of which received high severity ratings.

The bulletin identified CVE-2021-31854 and CVE-2022-0166, two high severity attack vectors that can leave any asset with McAfee ePO Agents deployed vulnerable to attack. Per the McAfee’s guidance, any implementations with Agents earlier than version 5.7.5 deployed should update the Agent or risk further exposure.

The security brief provides a detailed explanation of each CVE and cross-references the exploits against MITRE and National Institute of Standards and Technology (NIST) CVE reports.

  • CVE-2021-31854—A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.exe file is placed into the relevant folder and executed by running the McAfee Agent deployment feature located in the System Tree. An attacker may exploit the vulnerability to obtain a reverse shell which can lead to privilege escalation to obtain root privileges.
  • CVE-2022-0166—A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory within the installation directory. A low privilege user could have created subdirectories and executed arbitrary code with SYSTEM privileges by creating the appropriate pathway to the specifically created malicious openssl.cnf file.

McAfee has made Agent version 5.7.5 available to users and administrators tasked with remediating the vulnerabilities. The bulletin provides users of McAfee endpoint and ePO/server products with specific steps to determine whether or not their ePO and Agent implementation is vulnerable. Once deployed, any client machine with the Agent installed will no longer be susceptible to the identified exploits.

McAfee ePO is an administrative tool used to centralize the management of any endpoints (PCs, printers, other peripherals) on a user’s network. It provides administrators with the ability to centrally track and monitor various system data, events, and policies across all eligible endpoints within their environment.

Image credit: Pixelcreatures

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
The first electric pick-up R1T rewrites the game.  Rivian created a sophisticated machine that will stand up in the field and on the road thumbnail

The first electric pick-up R1T rewrites the game. Rivian created a sophisticated machine that will stand up in the field and on the road

Podobně jako před několika lety pobláznila celý svět automobilka Tesla se svým Modelem S, dnes na sebe značnou pozornost strhává Rivian se svou novinku, kterou je vůbec první elektrický pick-up na americkém trhu. Mladé a v podstatě stále neznámé automobilce se tím podařilo vypálit rybník i těm největším hráčům, jako je Ford, který svými pick-upy…
Read More
The first fine was imposed in Prague for renting via Airbnb.  Landlords should behave like hotels thumbnail

The first fine was imposed in Prague for renting via Airbnb. Landlords should behave like hotels

Praha je oblíbená turistická destinaceFoto: Jésshoots/Pexels Časy, kdy mělo Airbnb tak trochu nejasné místo v legislativě, se nejspíš blíží ke konci. Svědčí o tom mimo jiné dnešní rozhodnutí pražských úřadů, které vůbec poprvé udělily majiteli krátkodobě pronajímaného bytu pokutu ve výši 20 tisíc korun. Novinářům to dnes řekla radní Prahy pro bydlení Hana Marvanová. Podle…
Read More
The world can’t wean itself off Chinese lithium thumbnail

The world can’t wean itself off Chinese lithium

Enlarge / A customs officer inspects imported lithium carbonate at Longwu Branch Terminal of Shanghai İnternational Port Co., Ltd.The industrial port of Kwinana on Australia’s western coast is a microcosm of the global energy industry. From 1955, it was home to one of the largest oil refineries in the region, owned by British Petroleum when…
Read More
Publishers use subscriber-only events to sweeten subscription pitches thumbnail

Publishers use subscriber-only events to sweeten subscription pitches

As some publishers refrain from returning to in-person events just yet, they are employing their virtual events to aid another direct revenue source: subscriptions.The Washington Post launched its first event series exclusively for print and digital subscribers on Jan. 18. The Information is also adding to its subscriber-only events this month, with programming created for…
Read More
How to let Google Messages write texts for you with AI thumbnail

How to let Google Messages write texts for you with AI

Since Google I/O 2023, the push for AI in Google’s many different applications has been huge. One result of that finds itself in Google Messages, where you can let AI write a text for you. Here’s how. Within the last couple of months, Google Messages has started seeing a new feature appear in the app.
Read More
Index Of News
Total
0
Share