VulnerabilityModified
CVE-2015-1305
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
MEDIUM 6.9EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mcafee/data loss prevention endpoint
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/130177/McAfee-Data-Loss-Prevention-Endpoint-Privilege-Escalation.htmlExploit
- http://www.exploit-db.com/exploits/35953Exploit
- http://www.greyhathacker.net/?p=818Exploit
- http://www.osvdb.org/show/osvdb/117345
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100602
- https://kc.mcafee.com/corporate/index?page=content&id=SB10097Vendor Advisory
- http://packetstormsecurity.com/files/130177/McAfee-Data-Loss-Prevention-Endpoint-Privilege-Escalation.htmlExploit
- http://www.exploit-db.com/exploits/35953Exploit
- http://www.greyhathacker.net/?p=818Exploit
- http://www.osvdb.org/show/osvdb/117345
- https://exchange.xforce.ibmcloud.com/vulnerabilities/100602
- https://kc.mcafee.com/corporate/index?page=content&id=SB10097Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.