CVE-2022-1257: Improper Verification of Cryptographic Signature by McAfee Agent
Published Apr 14, 2022
·Updated
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through storage in ma.db. The sensitive information has been moved to encrypted database files.
Affected Software
1 affected component
McAfee Agent<5.7.6
Event History
Apr 14, 2022
CVE Published
via MITRE·01:50 PM
Data Sourced
via MITRE·01:50 PM
DescriptionSeverityWeakness
Jun 26, 2025
Exploit Published
12:00 AM
Known Exploited
06:33 PM
Frequently Asked Questions
1
What is CVE-2022-1257?
CVE-2022-1257 is an insecure storage of sensitive information vulnerability in McAfee Agent for Linux, macOS, and Windows prior to version 5.7.6.
2
How does CVE-2022-1257 impact the affected software?
CVE-2022-1257 allows a local user to gain access to sensitive information stored in ma.db.
3
Which versions of McAfee Agent are affected by CVE-2022-1257?
Versions of McAfee Agent prior to 5.7.6 are affected by CVE-2022-1257.
4
What is the severity of CVE-2022-1257?
CVE-2022-1257 has a severity value of 5.5, which is considered medium.
5
How can I fix CVE-2022-1257?
To fix CVE-2022-1257, upgrade to McAfee Agent version 5.7.6 or later.