CVE-2018-6706

CWE-3774 documents4 sources
Severity
7.5HIGH
EPSS
0.2%
top 62.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 12
Latest updateMay 13

Description

Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installation in Linux via unspecified vectors.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

CVEListV5mcafee/mcafee_agent_(ma)_for_linux5.0.05.0.0*+3
NVDmcafee/agent5.0.05.0.6+2

🔴Vulnerability Details

2
GHSA
GHSA-vw89-fw26-fj5r: Insecure handling of temporary files in non-Windows McAfee Agent 52022-05-13
CVEList
McAfee Agent (MA) non-Windows versions incorrect use of temporary file vulnerability2018-12-12

💥Exploits & PoCs

1
Exploit-DB
Microsoft Windows Defender - 'mpengine.dll' Memory Corruption2018-04-05