First published: Mon Feb 23 2015(Updated: )
The log viewer in McAfee Agent (MA) before 4.8.0 Patch 3 and 5.0.0, when the "Accept connections only from the ePO server" option is disabled, allows remote attackers to conduct clickjacking attacks via a crafted web page, aka an "http-generic-click-jacking" vulnerability.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Agent | <=4.8.0 | |
McAfee Agent | =5.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2053 is considered a medium severity vulnerability due to its potential for clickjacking attacks.
To resolve CVE-2015-2053, upgrade McAfee Agent to version 4.8.0 Patch 3 or later, or version 5.0.0.
CVE-2015-2053 affects McAfee Agent versions prior to 4.8.0 Patch 3 and version 5.0.0.
CVE-2015-2053 is associated with clickjacking attacks that can be executed through a malicious web page.
To mitigate CVE-2015-2053, ensure the 'Accept connections only from the ePO server' option is enabled.