CVE-2019-3622

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/07/2019
Last modified:
07/11/2023

Description

Files or Directories Accessible to External Parties in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows authenticated user to redirect DLPe log files to arbitrary locations via incorrect access control applied to the DLPe log folder allowing privileged users to create symbolic links.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:* 11.0 (including) 11.1.200 (excluding)
cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:*:*:* 11.2.000 (including) 11.3.0 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*