Description
Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13230 | Improper Neutralization of Special Elements used in a Command ('Command Injection') in ePO extension in McAfee Data Loss Prevention (DLP) 11.x prior to 11.3.0 allows Authenticated Adminstrator to execute arbitrary code with their local machine privileges via a specially crafted DLP policy, which is exported and opened on the their machine. In our checks, the user must explicitly allow the code to execute. |
References
History
Mon, 23 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | DLP Endpoint ePO extension not sanitizing CSV exports | DLP Endpoint ePO extension not sanitizing CSV exports |
Status: PUBLISHED
Assigner: trellix
Published:
Updated: 2024-08-04T19:12:09.605Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3595
No data.
Status : Modified
Published: 2019-07-24T15:15:12.180
Modified: 2024-11-21T04:42:13.880
Link: CVE-2019-3595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD