SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-31845

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a…

HIGH 7.3EPSS 1.12%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.12%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

A buffer overflow vulnerability in McAfee Data Loss Prevention (DLP) Discover prior to 11.6.100 allows an attacker in the same network as the DLP Discover to execute arbitrary code through placing carefully constructed Ami Pro (.sam) files onto a machine and having DLP Discover scan it, leading to remote code execution with elevated privileges. This is caused by the destination buffer being of fixed size and incorrect checks being made on the source size.

CVSS 3.1
7.3 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS
1.12% probability · 64th percentile
CISA KEV
Not listed
Weakness
CWE-120
Affected
mcafee/data loss prevention discover
Source
trellixpsirt@trellix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.