SB2018121215 - Use-after-free in agent



SB2018121215 - Use-after-free in agent

Published: December 12, 2018 Updated: August 8, 2020

Security Bulletin ID SB2018121215
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Use-after-free (CVE-ID: CVE-2018-6703)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.


Remediation

Install update from vendor's website.