First published: Thu Apr 15 2021(Updated: )
Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.
Credit: psirt@mcafee.com trellixpsirt@trellix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Data Loss Prevention Endpoint | <11.6.100.41 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-23886 is a Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to version 11.6.100.
CVE-2021-23886 allows a local, low privileged attacker to cause a BSoD (Blue Screen of Death) by suspending a process, modifying its memory, and restarting it.
Users of McAfee Data Loss Prevention (DLP) Endpoint for Windows versions prior to 11.6.100 are affected by CVE-2021-23886.
CVE-2021-23886 has a severity rating of 5.5 (Medium).
To mitigate CVE-2021-23886, it is recommended to update McAfee Data Loss Prevention (DLP) Endpoint for Windows to version 11.6.100.