Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2330

Опубликовано: 30 авг. 2022
Источник: nvd
CVSS3: 6.5
EPSS Низкий

Описание

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*
Версия до 11.6.600.212 (исключая)
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:*
Версия от 11.9.0 (включая) до 11.9.100 (исключая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 56%
0.00343
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 6.5
github
больше 3 лет назад

Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 and 11.6.600 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.

EPSS

Процентиль: 56%
0.00343
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-611
CWE-611