CVE-2021-23886

Denial of Service vulnerability in McAfee Data Loss Prevention (DLP) Endpoint for Windows prior to 11.6.100 allows a local, low privileged, attacker to cause a BSoD through suspending a process, modifying the processes memory and restarting it. This is triggered by the hdlphook driver reading invalid memory.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:windows:*:*

History

15 Nov 2023, 18:46

Type Values Removed Values Added
CWE CWE-755
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10357 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10357 - Broken Link
References () https://kc.mcafee.com/corporate/index?page=content&id=SB10354 - () https://kc.mcafee.com/corporate/index?page=content&id=SB10354 - Broken Link

07 Nov 2023, 03:30

Type Values Removed Values Added
CWE CWE-755
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10357 - Patch, Vendor Advisory () https://kc.mcafee.com/corporate/index?page=content&id=SB10357 -
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10354 - Not Applicable () https://kc.mcafee.com/corporate/index?page=content&id=SB10354 -

21 Apr 2021, 20:10

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 4.9
v3 : 5.5
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10354 - (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10354 - Not Applicable
References (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10357 - (CONFIRM) https://kc.mcafee.com/corporate/index?page=content&id=SB10357 - Patch, Vendor Advisory
CPE cpe:2.3:a:mcafee:data_loss_prevention_endpoint:*:*:*:*:*:windows:*:*

15 Apr 2021, 09:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-15 08:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-23886

Mitre link : CVE-2021-23886

CVE.ORG link : CVE-2021-23886


JSON object : View

Products Affected

mcafee

  • data_loss_prevention_endpoint
CWE
CWE-755

Improper Handling of Exceptional Conditions