Your review has been sent successfully

McAfee Updates

3063
Classification
These posts contain security alerts, including digital loopholes, electronic attacks, technical updates, and they are classified base on the level of severity.

Critical

High

Medium

Low

Warning Date

Severity Level

Warning Number

Target Sector

14 November, 2019

● High

2019-625

All

Description:

McAfee has released security updates to address multiple vulnerabilities in the following products:

  • Advanced Threat Defense (ATD) Version 4.6.x and earlier
  • Threat Intelligence Exchange (TIE) Server Version 3.0.0

Threats:

  • Attacker could exploit these vulnerabilities by doing the following:
  • Modify stored reputation data.
  • Access to files on the system remotely.
  • Gain access to ePO as an administrator.
  • Execute database commands remotely.
  • Access to passwords and hashed credentials via carefully constructed POST request remotely.
  • Gain access remotely to the root password via accessing sensitive files on the system.

Best practice and Recommendations:

The CERT team encourages users to review McAfee security advisory and apply the necessary updates: https://www.mcafee.com/enterprise/en-us/threat-center/product-security-bulletins.html

Last updated at 1 January, 2020

Rate the content

rate-icon
up icon