CVE-2021-23886: Local Denial of Service in McAfee DLP Endpoint for Windows
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-23886?
CVE-2021-23886 is a Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to version 11.6.100.
How does CVE-2021-23886 impact the system?
CVE-2021-23886 allows a local, low privileged attacker to cause a BSoD (Blue Screen of Death) by suspending a process, modifying its memory, and restarting it.
Who is affected by CVE-2021-23886?
Users of McAfee Data Loss Prevention (DLP) Endpoint for Windows versions prior to 11.6.100 are affected by CVE-2021-23886.
What is the severity of CVE-2021-23886?
CVE-2021-23886 has a severity rating of 5.5 (Medium).
How can I fix CVE-2021-23886?
To mitigate CVE-2021-23886, it is recommended to update McAfee Data Loss Prevention (DLP) Endpoint for Windows to version 11.6.100.