Show filters
31 Total Results
Displaying 11-20 of 31
Sort by:
Attacker Value
Unknown
DLP Endpoint Windows lock screen bypass with physical access
Disclosure Date: July 25, 2019 (last updated November 08, 2023)
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to the machine.
0
Attacker Value
Unknown
DLP Endpoint log file redirection to arbitrary locations
Disclosure Date: July 24, 2019 (last updated November 08, 2023)
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.
0
Attacker Value
Unknown
DLP Endpoint ePO extension not sanitizing CSV exports
Disclosure Date: July 24, 2019 (last updated November 08, 2023)
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
0
Attacker Value
Unknown
DLP Endpoint ePO extension vulnerable to XSS
Disclosure Date: July 24, 2019 (last updated November 08, 2023)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in ePO extension in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows unauthenticated remote user to trigger specially crafted JavaScript to render in the ePO UI via a carefully crafted upload to a remote website which is correctly blocked by DLPe Web Protection. This would then render as an XSS when the DLP Admin viewed the event in the ePO UI.
0
Attacker Value
Unknown
Data Loss Prevention Endpoint (DLPe) - Authentication Bypass vulnerability
Disclosure Date: October 03, 2018 (last updated November 08, 2023)
Authentication Bypass vulnerability in McAfee Data Loss Prevention Endpoint (DLPe) 10.0.x earlier than 10.0.510, and 11.0.x earlier than 11.0.600 allows attackers to bypass local security protection via specific conditions.
0
Attacker Value
Unknown
- Data Loss Prevention (DLP) for Windows - Exploiting Incorrectly Configured A…
Disclosure Date: July 23, 2018 (last updated November 08, 2023)
Exploiting Incorrectly Configured Access Control Security Levels vulnerability in McAfee Data Loss Prevention (DLP) for Windows versions prior to 10.0.505 and 11.0.405 allows local users to bypass DLP policy via editing of local policy files when offline.
0
Attacker Value
Unknown
SB10233 - Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint …
Disclosure Date: May 25, 2018 (last updated November 08, 2023)
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.
0
Attacker Value
Unknown
CVE-2017-3948
Disclosure Date: June 23, 2017 (last updated November 26, 2024)
Cross Site Scripting (XSS) in IMG Tags in the ePO extension in McAfee Data Loss Prevention Endpoint (DLP Endpoint) 10.0.x allows authenticated users to inject arbitrary web script or HTML via injecting malicious JavaScript into a user's browsing session.
0
Attacker Value
Unknown
CVE-2016-8012
Disclosure Date: March 14, 2017 (last updated November 26, 2024)
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get.
0
Attacker Value
Unknown
CVE-2016-3984
Disclosure Date: April 08, 2016 (last updated November 25, 2024)
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
0