First published: Fri Feb 06 2015(Updated: )
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Data Loss Prevention Endpoint | <=9.3.300 | |
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-1305 has a high severity rating due to its potential for privilege escalation.
To fix CVE-2015-1305, upgrade to McAfee Data Loss Prevention Endpoint version 9.3.400 or later.
CVE-2015-1305 affects users of McAfee Data Loss Prevention Endpoint versions prior to 9.3.400.
CVE-2015-1305 is a privilege escalation vulnerability that allows local users to write to arbitrary memory locations.
CVE-2015-1305 cannot be exploited remotely as it requires local access to the affected system.