CVE-2019-3622Files or Directories Accessible to External Parties in LLC Data Loss Prevention FOR Windows

Severity
8.2HIGHNVD
EPSS
0.1%
top 75.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateMay 24

Description

Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:HExploitability: 1.5 | Impact: 6.0

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-mmr7-4p3g-gvjm: Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 112022-05-24
CVEList
DLP Endpoint log file redirection to arbitrary locations2019-07-24