Back

CRITICAL

Remote Logging functionality had a use after free vulnerability in McAfee Agent

Published Dec 11, 2018

Description

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.

Affected products

Remediation

Vendor solution

Remote logging is disabled by default. Turning off remote logging protects against this issue.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trellix
Published Dec 11, 2018
Updated Aug 5, 2024
Reserved Feb 6, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a