CVE-2021-31842: Medium severity mcafee endpoint security vulnerability
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-31842?
CVE-2021-31842 is an XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to version 10.7.0 September 2021 Update.
How does CVE-2021-31842 affect McAfee Endpoint Security?
CVE-2021-31842 allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing.
What is the severity of CVE-2021-31842?
CVE-2021-31842 has a severity level of medium with a CVSS score of 5.5.
Which versions of McAfee Endpoint Security are affected by CVE-2021-31842?
McAfee Endpoint Security versions prior to 10.7.0 September 2021 Update are affected by CVE-2021-31842.
How can I fix CVE-2021-31842 vulnerability?
To fix CVE-2021-31842, users should update their McAfee Endpoint Security to version 10.7.0 September 2021 Update or later.