Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-31845

Опубликовано: 17 сент. 2021
Источник: nvd
CVSS3: 8.4
CVSS3: 7.3
CVSS2: 6
EPSS Низкий

Описание

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:mcafee:data_loss_prevention_discover:*:*:*:*:*:*:*:*
Версия до 11.6.100 (исключая)
cpe:2.3:a:mcafee:data_loss_prevention_discover:*:*:*:*:*:*:*:*
Версия от 11.7.0 (включая) до 11.7.100 (исключая)

EPSS

Процентиль: 76%
0.00962
Низкий

8.4 High

CVSS3

7.3 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-120
CWE-120

Связанные уязвимости

CVSS3: 7.3
github
больше 3 лет назад

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

EPSS

Процентиль: 76%
0.00962
Низкий

8.4 High

CVSS3

7.3 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-120
CWE-120