Agent
Vendor:
First CVE: Mar 17, 2008 · Active for 18 years
25
Total CVEs
More Total CVEs than 95% of tracked products
2.8
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 34% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Agent over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 17, 2008
18 years ago
Most Recent CVE
Jul 27, 2022
1,458 days ago
CVE Severity & Scoring
Agent25 CVEs
40%
52%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local15 (60.0%)
Network8 (32.0%)
Unknown2 (8.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low20 (80.0%)
High3 (12.0%)
Unknown2 (8.0%)
User Interaction
None18 (72.0%)
Unknown2 (8.0%)
Required5 (20.0%)
Privileges Required
Low11 (44.0%)
High4 (16.0%)
None8 (32.0%)
Unknown2 (8.0%)
Top CVEs
Signals from CVEs in this product scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-6703CRITICAL Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service | Dec 11, 2018 | 9.8 | 32 | NO | NO |
CVE-2022-1257MEDIUM Insecure storage of sensitive information vulnerability in MA for Linux, macOS, and Windows prior to 5.7.6 allows a local user to gain access to sensitive information through stora | Apr 14, 2022 | 5.5 | 30 | NO | YES |
CVE-2019-1559MEDIUM If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently | Feb 27, 2019 | 5.9 | 30 | NO | NO |
CVE-2022-2313HIGH A DLL hijacking vulnerability in the MA Smart Installer for Windows prior to 5.7.7, which allows local users to execute arbitrary code and obtain higher privileges via careful plac | Jul 27, 2022 | 7.3 | 27 | NO | NO |
CVE-2021-1257HIGH A vulnerability in the web-based management interface of Cisco DNA Center Software could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) at | Jan 20, 2021 | 8.8 | 27 | NO | NO |
CVE-2016-3984MEDIUM The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) | Apr 8, 2016 | 5.1 | 27 | NO | YES |
CVE-2022-0166HIGH A privilege escalation vulnerability in the McAfee Agent prior to 5.7.5. McAfee Agent uses openssl.cnf during the build process to specify the OPENSSLDIR variable as a subdirectory | Jan 19, 2022 | 7.8 | 26 | NO | NO |
CVE-2021-31854HIGH A command Injection Vulnerability in McAfee Agent (MA) for Windows prior to 5.7.5 allows local users to inject arbitrary shell code into the file cleanup.exe. The malicious clean.e | Jan 19, 2022 | 7.8 | 26 | NO | NO |
CVE-2019-3599HIGH Information Disclosure vulnerability in Remote logging (which is disabled by default) in McAfee Agent (MA) 5.x allows remote unauthenticated users to access sensitive information v | Feb 28, 2019 | 7.5 | 25 | NO | NO |
CVE-2018-6706HIGH Insecure handling of temporary files in non-Windows McAfee Agent 5.0.0 through 5.0.6, 5.5.0, and 5.5.1 allows an Unprivileged User to introduce custom paths during agent installati | Dec 12, 2018 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (25 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
12.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (25 CVEs).
Media Mentions
Signals from CVEs in this product scope (25 CVEs).
Top CNAs Publishing CVEs For Agent
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.6.0 | 2 | 6.4 | 1.8% | 0 | 0 |
| 5.5.1 | 4 | 7.5 | 0.4% | 0 | 0 |
| 5.5.0 | 4 | 7.5 | 0.4% | 0 | 0 |
| 4.0 | 1 | 5.4 | 6.2% | 0 | 1 |