Use-after-free in agent - CVE-2018-6703
Published: December 12, 2018 / Updated: August 8, 2020
agent
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.