First published: Tue Mar 14 2017(Updated: )
Access control vulnerability in Intel Security Data Loss Prevention Endpoint (DLPe) 9.4.200 and 9.3.600 allows authenticated users with Read-Write-Execute permissions to inject hook DLLs into other processes via pages in the target process memory get.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention Endpoint | >=9.3.0<=9.3.600 | |
Mcafee Data Loss Prevention Endpoint | >=9.4.0<=9.4.200 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8012 is considered a medium severity vulnerability due to its impact on access control.
To fix CVE-2016-8012, upgrade affected Intel Security Data Loss Prevention Endpoint software to version 9.4.201 or higher.
CVE-2016-8012 affects McAfee Data Loss Prevention Endpoint versions 9.3.0 to 9.3.600 and 9.4.0 to 9.4.200.
CVE-2016-8012 exploits the vulnerability in access control allowing authenticated users to inject DLLs into other processes.
Organizations using McAfee Data Loss Prevention Endpoint versions 9.3.600 and 9.4.200 are at risk due to CVE-2016-8012.