漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Local Privilege Escalation in McAfee DLP Endpoint for Windows
Vulnerability Description
A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.200 allows a local attacker to execute arbitrary code with elevated privileges through placing carefully constructed Ami Pro (.sam) files onto the local system and triggering a DLP Endpoint scan through accessing a file. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Vulnerability Type
未进行输入大小检查的缓冲区拷贝(传统缓冲区溢出)
Vulnerability Title
McAfee Data Loss Prevention 安全漏洞
Vulnerability Description
Mcafee McAfee Data Loss Prevention(DLP)是美国迈克菲(Mcafee)公司的一套数据丢失防护套件,它包含McAfee DLP Monitor、McAfee DLP Endpoint等组件,并提供事件管理和报告、同步本地和云DLP策略等功能。 Data Loss Prevention (DLP) Endpoint存在安全漏洞,该漏洞源于网络系统或产品在内存上执行操作时,未正确验证数据边界,导致向关联的其他内存位置上执行了错误的读写操作。攻击者可利用该漏洞导致缓冲区溢出或堆
CVSS Information
N/A
Vulnerability Type
N/A