McAfee Updates
3063Warning Date
Severity Level
Warning Number
Target Sector
14 November, 2019
● High
2019-625
All
Description:
McAfee has released security updates to address multiple vulnerabilities in the following products:
- Advanced Threat Defense (ATD) Version 4.6.x and earlier
- Threat Intelligence Exchange (TIE) Server Version 3.0.0
Threats:
- Attacker could exploit these vulnerabilities by doing the following:
- Modify stored reputation data.
- Access to files on the system remotely.
- Gain access to ePO as an administrator.
- Execute database commands remotely.
- Access to passwords and hashed credentials via carefully constructed POST request remotely.
- Gain access remotely to the root password via accessing sensitive files on the system.
Best practice and Recommendations:
The CERT team encourages users to review McAfee security advisory and apply the necessary updates: https://www.mcafee.com/enterprise/en-us/threat-center/product-security-bulletins.html