Use-after-free in agent - CVE-2018-6703

 

Use-after-free in agent - CVE-2018-6703

Published: December 12, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU36302
CSH Severity: High
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber
CVE-ID: CVE-2018-6703
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Ilya Grigorik
Affected software:
agent

Detailed vulnerability description

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.


How to mitigate CVE-2018-6703

Install update from vendor's website.

Sources