CVE-2021-23887: Privilege escalation in McAfee DLP Endpoint for Windows
Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-23887?
The severity of CVE-2021-23887 is high with a CVSS score of 7.8.
What is the affected software for CVE-2021-23887?
The affected software for CVE-2021-23887 is McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to version 11.6.100.41.
How does the vulnerability in CVE-2021-23887 work?
The vulnerability in CVE-2021-23887 allows a local, low privileged attacker to write to arbitrary controlled kernel addresses by launching applications, suspending them, modifying the memory, and restarting.
Is there a fix available for CVE-2021-23887?
Yes, a fix for CVE-2021-23887 is available in McAfee Data Loss Prevention (DLP) Endpoint version 11.6.100.41 and above.
Where can I find more information about CVE-2021-23887?
More information about CVE-2021-23887 can be found on the official McAfee website at the following links: [McAfee Security Bulletin SB10354](https://kc.mcafee.com/corporate/index?page=content&id=SB10354) and [McAfee Security Bulletin SB10357](https://kc.mcafee.com/corporate/index?page=content&id=SB10357).