First published: Tue Mar 14 2017(Updated: )
Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Agent | <=4.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-8987 has a high severity rating due to its potential for exploitation in a man-in-the-middle (MitM) attack.
To fix CVE-2015-8987, upgrade the McAfee Agent to version 4.8.0 patch 3 or later.
CVE-2015-8987 affects McAfee Agent versions 4.8.0 and earlier on non-Mac OS systems.
Yes, CVE-2015-8987 allows attackers to make a McAfee Agent communicate with rogue ePO servers through MitM techniques.
There have been no reported cases of exploitation for CVE-2015-8987, but it remains a critical risk.