CVE-2018-6703

Severity CVSS v4.0:
Pending analysis
Type:
CWE-416 Use After Free
Publication date:
11/12/2018
Last modified:
07/11/2023

Description

Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:agent:*:*:*:*:*:*:*:* 5.0.0 (including) 5.6.0 (excluding)


References to Advisories, Solutions, and Tools