Multiple vulnerabilities in McAfee Web Gateway



Published: 2018-06-15
Risk High
Patch available YES
Number of vulnerabilities 5
CVE ID CVE-2018-6667
CVE-2018-1124
CVE-2017-12942
CVE-2017-12941
CVE-2017-12940
CWE ID CWE-20
CWE-190
CWE-119
CWE-125
Exploitation vector Network
Public exploit N/A
Vulnerable software
Subscribe
McAfee Web Gateway
Server applications / Remote management servers, RDP, SSH

Vendor McAfee

Security Advisory

1) Authentication bypass

Risk: High

CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2018-6667

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass authentication and execute arbitrary code on the target system.

The vulnerability exists due to insufficient validation of user-supplied input. A remote unauthenticated attacker can send specially crafted data to the Java management extensions (JMX) service on the administrative user interface via TCP port 1099, bypass authentication and execute arbitrary code.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update to version 7.8.1.6.

Vulnerable software versions

McAfee Web Gateway: 7.8.1.0, 7.8.1.1, 7.8.1.2, 7.8.1.3, 7.8.1.4, 7.8.1.5

CPE External links

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Integer overflow

Risk: Low

CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2018-1124

CWE-ID: CWE-190 - Integer Overflow or Wraparound

Exploit availability: No

Description

The vulnerability allows a local attacker to gain elevated privileges on the target system.

The weakness exists due to integer overflow in libprocps's file2strvec() function. A local attacker can execute a vulnerable utility (pgrep, pidof, pkill, and w are vulnerable by default; other utilities are vulnerable if executed with non-default options) and gain elevated privileges.

Mitigation

Update to version 7.7.2.14, 7.8.1.6.

Vulnerable software versions

McAfee Web Gateway: 7.6.0.0, 7.6.0.1, 7.6.1, 7.6.1.1, 7.6.1.2, 7.6.1.3, 7.6.2, 7.6.2.1, 7.6.2.2, 7.6.2.3, 7.6.2.4, 7.6.2.5, 7.6.2.6, 7.6.2.7, 7.6.2.8, 7.6.2.9, 7.6.2.10, 7.6.2.11, 7.6.2.12, 7.6.2.13, 7.6.2.14, 7.6.2.15, 7.6.2.16, 7.6.2.17, 7.6.2.18, 7.6.2.19, 7.7.0, 7.7.0.1, 7.7.0.2, 7.7.0.3, 7.7.1, 7.7.1.1, 7.7.1.2, 7.7.1.3, 7.7.1.4, 7.7.1.5, 7.7.2, 7.7.2.1, 7.7.2.2, 7.7.2.3, 7.7.2.4, 7.7.2.5, 7.7.2.6, 7.7.2.7, 7.7.2.8, 7.7.2.9, 7.7.2.10, 7.7.2.11, 7.7.2.12, 7.7.2.13, 7.8.1.0, 7.8.1.1, 7.8.1.2, 7.8.1.3, 7.8.1.4, 7.8.1.5

CPE External links

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

The attacker would have to login to the system and perform certain actions in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Buffer overflow

Risk: High

CVSSv3.1: 8.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-12942

CWE-ID: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to boundary error when processing archives in in the Unpack::LongLZ function in libunrar.a in UnRAR before 5.5.7. A remote unauthenticated attacker can create a specially crafted archive, trick the victim into opening it an execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Update to version 7.7.2.14, 7.8.1.6.

Vulnerable software versions

McAfee Web Gateway: 7.6.0.0, 7.6.0.1, 7.6.1, 7.6.1.1, 7.6.1.2, 7.6.1.3, 7.6.2, 7.6.2.1, 7.6.2.2, 7.6.2.3, 7.6.2.4, 7.6.2.5, 7.6.2.6, 7.6.2.7, 7.6.2.8, 7.6.2.9, 7.6.2.10, 7.6.2.11, 7.6.2.12, 7.6.2.13, 7.6.2.14, 7.6.2.15, 7.6.2.16, 7.6.2.17, 7.6.2.18, 7.6.2.19, 7.7.0, 7.7.0.1, 7.7.0.2, 7.7.0.3, 7.7.1, 7.7.1.1, 7.7.1.2, 7.7.1.3, 7.7.1.4, 7.7.1.5, 7.7.2, 7.7.2.1, 7.7.2.2, 7.7.2.3, 7.7.2.4, 7.7.2.5, 7.7.2.6, 7.7.2.7, 7.7.2.8, 7.7.2.9, 7.7.2.10, 7.7.2.11, 7.7.2.12, 7.7.2.13, 7.8.1.0, 7.8.1.1, 7.8.1.2, 7.8.1.3, 7.8.1.4, 7.8.1.5

CPE External links

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Out-of-bounds read

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-12941

CWE-ID: CWE-125 - Out-of-bounds Read

Exploit availability: No

Description

The vulnerability allows a remote attacker to crash the affected application.

The vulnerability exists due to out-of-bounds read in libunrar.a in UnRAR before 5.5.7 in the Unpack::Unpack20 function. A remote attacker can create a specially crafted archive and crash the affected application.

Mitigation

Update to version 7.7.2.14, 7.8.1.6.

Vulnerable software versions

McAfee Web Gateway: 7.6.0.0, 7.6.0.1, 7.6.1, 7.6.1.1, 7.6.1.2, 7.6.1.3, 7.6.2, 7.6.2.1, 7.6.2.2, 7.6.2.3, 7.6.2.4, 7.6.2.5, 7.6.2.6, 7.6.2.7, 7.6.2.8, 7.6.2.9, 7.6.2.10, 7.6.2.11, 7.6.2.12, 7.6.2.13, 7.6.2.14, 7.6.2.15, 7.6.2.16, 7.6.2.17, 7.6.2.18, 7.6.2.19, 7.7.0, 7.7.0.1, 7.7.0.2, 7.7.0.3, 7.7.1, 7.7.1.1, 7.7.1.2, 7.7.1.3, 7.7.1.4, 7.7.1.5, 7.7.2, 7.7.2.1, 7.7.2.2, 7.7.2.3, 7.7.2.4, 7.7.2.5, 7.7.2.6, 7.7.2.7, 7.7.2.8, 7.7.2.9, 7.7.2.10, 7.7.2.11, 7.7.2.12, 7.7.2.13, 7.8.1.0, 7.8.1.1, 7.8.1.2, 7.8.1.3, 7.8.1.4, 7.8.1.5

CPE External links

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Out-of-bounds read

Risk: Low

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2017-12940

CWE-ID: CWE-125 - Out-of-bounds Read

Exploit availability: No

Description

The vulnerability allows a remote attacker to crash the affected application.

The vulnerability exists due to out-pf-bounds read in libunrar.a in UnRAR before 5.5.7 in the EncodeFileName::Decode call within the Archive::ReadHeader15 function. A remote attacker can create a specially crafted archive and crash the affected application.

Mitigation

Update to version 7.7.2.14, 7.8.1.6.

Vulnerable software versions

McAfee Web Gateway: 7.6.0.0, 7.6.0.1, 7.6.1, 7.6.1.1, 7.6.1.2, 7.6.1.3, 7.6.2, 7.6.2.1, 7.6.2.2, 7.6.2.3, 7.6.2.4, 7.6.2.5, 7.6.2.6, 7.6.2.7, 7.6.2.8, 7.6.2.9, 7.6.2.10, 7.6.2.11, 7.6.2.12, 7.6.2.13, 7.6.2.14, 7.6.2.15, 7.6.2.16, 7.6.2.17, 7.6.2.18, 7.6.2.19, 7.7.0, 7.7.0.1, 7.7.0.2, 7.7.0.3, 7.7.1, 7.7.1.1, 7.7.1.2, 7.7.1.3, 7.7.1.4, 7.7.1.5, 7.7.2, 7.7.2.1, 7.7.2.2, 7.7.2.3, 7.7.2.4, 7.7.2.5, 7.7.2.6, 7.7.2.7, 7.7.2.8, 7.7.2.9, 7.7.2.10, 7.7.2.11, 7.7.2.12, 7.7.2.13, 7.8.1.0, 7.8.1.1, 7.8.1.2, 7.8.1.3, 7.8.1.4, 7.8.1.5

CPE External links

https://kc.mcafee.com/corporate/index?page=content&id=SB10241

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###