First published: Wed Jul 24 2019(Updated: )
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention Endpoint | >=11.0<11.1.200 | |
Mcafee Data Loss Prevention Endpoint | >=11.2.000<11.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2019-3595.
CVE-2019-3595 has a severity of 6.5 (medium).
The affected software for CVE-2019-3595 is McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0.
CVE-2019-3595 allows an Authenticated Administrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0.
Yes, you can find more information about CVE-2019-3595 at the following links: [SecurityFocus](http://www.securityfocus.com/bid/109377) and [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10289).