{ "id": "CVE-2021-23878", "sourceIdentifier": "psirt@mcafee.com", "published": "2021-02-10T09:15:13.090", "lastModified": "2021-02-16T18:23:45.867", "vulnStatus": "Analyzed", "descriptions": [ { "lang": "en", "value": "Clear text storage of sensitive Information in memory vulnerability in McAfee Endpoint Security (ENS) for Windows prior to 10.7.0 February 2021 Update allows a local user to view ENS settings and credentials via accessing process memory after the ENS administrator has performed specific actions. To exploit this, the local user has to access the relevant memory location immediately after an ENS administrator has made a configuration change through the console on their machine" }, { "lang": "es", "value": "Una vulnerabilidad de almacenamiento en texto sin cifrar de informaci\u00f3n confidencial en la memoria en McAfee Endpoint Security (ENS) para Windows versiones anteriores a 10.7.0, la actualizaci\u00f3n de Febrero de 2021, permite a un usuario local visualizar la configuraci\u00f3n y las credenciales de ENS por medio del acceso a la memoria del proceso despu\u00e9s de que el administrador de ENS haya llevado a cabo acciones espec\u00edficas. Para explotar esto, el usuario local debe acceder a la ubicaci\u00f3n de memoria relevante inmediatamente despu\u00e9s de a un administrador de ENS haya realizado un cambio de configuraci\u00f3n por medio de la consola en su m\u00e1quina" } ], "metrics": { "cvssMetricV31": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 5.0, "baseSeverity": "MEDIUM" }, "exploitabilityScore": 1.3, "impactScore": 3.6 }, { "source": "psirt@mcafee.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "LOW", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseScore": 7.3, "baseSeverity": "HIGH" }, "exploitabilityScore": 1.3, "impactScore": 5.9 } ], "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": true } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-312" } ] }, { "source": "psirt@mcafee.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-312" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:mcafee:endpoint_security:*:*:*:*:*:windows:*:*", "versionEndExcluding": "10.7.0", "matchCriteriaId": "CA4CEE25-A297-4D69-8CF8-5425875B206A" } ] } ] } ], "references": [ { "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10345", "source": "psirt@mcafee.com", "tags": [ "Vendor Advisory" ] } ] }