CVE-2015-1305: Medium severity symantec data loss prevention vulnerability
Published Feb 6, 2015
·Updated
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
Affected Software
2 affected components
McAfee Data Loss Prevention Endpoint<=9.3.300
Microsoft Windows XP
Event History
Feb 6, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-1305?
CVE-2015-1305 has a high severity rating due to its potential for privilege escalation.
2
How do I fix CVE-2015-1305?
To fix CVE-2015-1305, upgrade to McAfee Data Loss Prevention Endpoint version 9.3.400 or later.
3
Who is affected by CVE-2015-1305?
CVE-2015-1305 affects users of McAfee Data Loss Prevention Endpoint versions prior to 9.3.400.
4
What type of vulnerability is CVE-2015-1305?
CVE-2015-1305 is a privilege escalation vulnerability that allows local users to write to arbitrary memory locations.
5
Can CVE-2015-1305 be exploited remotely?
CVE-2015-1305 cannot be exploited remotely as it requires local access to the affected system.