CVE-2021-31842
17.09.2021, 14:15
XML Entity Expansion injection vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 September 2021 Update allows a local user to initiate high CPU and memory consumption resulting in a Denial of Service attack through carefully editing the EPDeploy.xml file and then executing the setup process.
Vendor | Product | Version |
---|---|---|
mcafee | endpoint_security | 𝑥 < 10.7.0 |
mcafee | endpoint_security | 10.7.0:april_2020 |
mcafee | endpoint_security | 10.7.0:april_2021 |
mcafee | endpoint_security | 10.7.0:february_2020 |
mcafee | endpoint_security | 10.7.0:february_2021 |
mcafee | endpoint_security | 10.7.0:july_2020 |
mcafee | endpoint_security | 10.7.0:june_2021 |
mcafee | endpoint_security | 10.7.0:november_2020 |
mcafee | endpoint_security | 10.7.0:september_2020 |
𝑥
= Vulnerable software versions