CVE-2019-3621

Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to the machine.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
PHYSICAL
HIGH
HIGH
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
trellixCNA
6.8 MEDIUM
PHYSICAL
HIGH
HIGH
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
mcafeedata_loss_prevention_endpoint
11.0 ≤
𝑥
< 11.1.200
mcafeedata_loss_prevention_endpoint
11.2.000 ≤
𝑥
< 11.3.0
𝑥
= Vulnerable software versions