CVE-2015-2053: Input Validation
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web page, aka an "http-generic-click-jacking" vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2053?
CVE-2015-2053 is considered a medium severity vulnerability due to its potential for clickjacking attacks.
How do I fix CVE-2015-2053?
To resolve CVE-2015-2053, upgrade McAfee Agent to version 4.8.0 Patch 3 or later, or version 5.0.0.
Which versions of McAfee Agent are affected by CVE-2015-2053?
CVE-2015-2053 affects McAfee Agent versions prior to 4.8.0 Patch 3 and version 5.0.0.
What type of attack is associated with CVE-2015-2053?
CVE-2015-2053 is associated with clickjacking attacks that can be executed through a malicious web page.
What option should be enabled to mitigate CVE-2015-2053?
To mitigate CVE-2015-2053, ensure the 'Accept connections only from the ePO server' option is enabled.