First published: Thu Apr 14 2022(Updated: )
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Agent | <5.7.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-1257 is an insecure storage of sensitive information vulnerability in McAfee Agent for Linux, macOS, and Windows prior to version 5.7.6.
CVE-2022-1257 allows a local user to gain access to sensitive information stored in ma.db.
Versions of McAfee Agent prior to 5.7.6 are affected by CVE-2022-1257.
CVE-2022-1257 has a severity value of 5.5, which is considered medium.
To fix CVE-2022-1257, upgrade to McAfee Agent version 5.7.6 or later.