CVE-2019-3595: DLP Endpoint ePO extension not sanitizing CSV exports
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-3595.
What is the severity of CVE-2019-3595?
CVE-2019-3595 has a severity of 6.5 (medium).
What is the affected software for CVE-2019-3595?
The affected software for CVE-2019-3595 is McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0.
How does CVE-2019-3595 work?
CVE-2019-3595 allows an Authenticated Administrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0.
Are there any references for CVE-2019-3595?
Yes, you can find more information about CVE-2019-3595 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/109377) and [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10289).