Rewterz

Rewterz Threat Advisory – Multiple Kubernetes Vulnerabilites

April 15, 2021
Rewterz

Rewterz Threat Advisory – ICS: Siemens Nucleus Products DNS Module

April 16, 2021

Rewterz Threat Advisory – McAfee (DLP) Endpoint for Windows Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2021-23886

Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.

CVE-2021-23887

Privilege Escalation vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to write to arbitrary controlled kernel addresses. This is achieved by launching applications, suspending them, modifying the memory and restarting them when they are monitored by McAfee DLP through the hdlphook driver.

Impact

  • Improper Handling of Exceptional Conditions
  • Privilege escalation 

Affected Vendors

McAfee

Affected Products

(DLP) Endpoint for Windows Prior to HF 11.6.100.41

Remediation

To remediate this issue, customers should update to DLP Endpoint for Windows HF 11.6.100.41.

Product Downloads site,

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.