Agent

Vendor:

First CVE: Mar 17, 2008 · Active for 18 years

25
Total CVEs
More Total CVEs than 95% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Agent over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 17, 2008
18 years ago
Most Recent CVE
Jul 27, 2022
1,458 days ago

CVE Severity & Scoring

Agent25 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local15 (60.0%)
Network8 (32.0%)
Unknown2 (8.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (80.0%)
High3 (12.0%)
Unknown2 (8.0%)
User Interaction
None18 (72.0%)
Unknown2 (8.0%)
Required5 (20.0%)
Privileges Required
Low11 (44.0%)
High4 (16.0%)
None8 (32.0%)
Unknown2 (8.0%)

Top CVEs

Signals from CVEs in this product scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service
Dec 11, 20189.832NONO
Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through stora
Apr 14, 20225.530NOYES
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently
Feb 27, 20195.930NONO
A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful plac
Jul 27, 20227.327NONO
A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) at
Jan 20, 20218.827NONO
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL)
Apr 8, 20165.127NOYES
A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory
Jan 19, 20227.826NONO
A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.e
Jan 19, 20227.826NONO
Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information v
Feb 28, 20197.525NONO
Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installati
Dec 12, 20187.525NONO

Exploit Exposure

Signals from CVEs in this product scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
12.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (25 CVEs).

Media Mentions

Signals from CVEs in this product scope (25 CVEs).

Top CNAs Publishing CVEs For Agent

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.6.026.41.8%00
5.5.147.50.4%00
5.5.047.50.4%00
4.015.46.2%01