CVE-2019-3622: DLP Endpoint log file redirection to arbitrary locations
Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3622?
The severity of CVE-2019-3622 is high with a severity value of 8.2.
How can an authenticated user exploit CVE-2019-3622?
An authenticated user can exploit CVE-2019-3622 by redirecting DLPe log files to arbitrary locations via incorrect access control.
What software versions are affected by CVE-2019-3622?
McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 is affected by CVE-2019-3622.
How can I fix CVE-2019-3622?
Update McAfee Data Loss Prevention (DLPe) for Windows to version 11.3.0 or later to fix CVE-2019-3622.
Where can I find more information about CVE-2019-3622?
You can find more information about CVE-2019-3622 at the following references: [SecurityFocus](http://www.securityfocus.com/bid/109370), [McAfee Knowledge Center](https://kc.mcafee.com/corporate/index?page=content&id=SB10290).