CVE-2015-8987: Medium severity mcafee agent vulnerability
Man-in-the-middle (MitM) attack vulnerability in non-Mac OS agents in McAfee (now Intel Security) Agent (MA) 4.8.0 patch 2 and earlier allows attackers to make a McAfee Agent talk with another, possibly rogue, ePO server via McAfee Agent migration to another ePO server.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-8987?
CVE-2015-8987 has a high severity rating due to its potential for exploitation in a man-in-the-middle (MitM) attack.
How do I fix CVE-2015-8987?
To fix CVE-2015-8987, upgrade the McAfee Agent to version 4.8.0 patch 3 or later.
What systems are affected by CVE-2015-8987?
CVE-2015-8987 affects McAfee Agent versions 4.8.0 and earlier on non-Mac OS systems.
Can CVE-2015-8987 allow attackers to impersonate ePO servers?
Yes, CVE-2015-8987 allows attackers to make a McAfee Agent communicate with rogue ePO servers through MitM techniques.
Is there any reported exploitation of CVE-2015-8987?
There have been no reported cases of exploitation for CVE-2015-8987, but it remains a critical risk.