CVE-2018-6664
Last modified
CVE-2018-6664 is a medium-severity vulnerability rated 5.8/10 on the CVSS scale. Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.. EPSS estimates a 0.71% chance of exploitation in the next 30 days.
Description
Application Protections Bypass vulnerability in Microsoft Windows in McAfee Data Loss Prevention (DLP) Endpoint before 10.0.500 and DLP Endpoint before 11.0.400 allows authenticated users to bypass the product block action via a command-line utility.
Metrics
CVSS:3.0/AV:P/AC:H/PR:L/UI:R/S:U/C:H/I:L/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Data Loss Prevention Endpoint | < 10.0.500 |
| Mcafee | Data Loss Prevention Endpoint | < 11.0.400 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6664?
How severe is CVE-2018-6664?
How do I fix CVE-2018-6664?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-6655PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS v…
- CVE-2018-6656Z-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_d…
- CVE-2018-6659Reflected Cross-Site Scripting vulnerability in McAfee ePoli…3.7
- CVE-2018-6660Directory Traversal vulnerability in McAfee ePolicy Orchestr…6.2
- CVE-2018-6661DLL Side-Loading vulnerability in Microsoft Windows Client i…7.8
- CVE-2018-6662Privilege Escalation vulnerability in McAfee Management of N…7.8
- CVE-2018-6667Authentication Bypass vulnerability in the administrative us…10
- CVE-2018-6668A whitelist bypass vulnerability in McAfee Application Contr…6.1
- CVE-2018-6669A whitelist bypass vulnerability in McAfee Application Contr…6.3
- CVE-2018-6670External Entity Attack vulnerability in the ePO extension in…7.6
- CVE-2018-6671Application Protection Bypass vulnerability in McAfee ePolic…4.7
- CVE-2018-6672Information disclosure vulnerability in McAfee ePolicy Orche…5.7
Are you affected by CVE-2018-6664?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
