A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
Advisories
Source ID Title
EUVD EUVD EUVD-2024-31924 A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
Fixes

Solution

There are two things required to remediate the bypass: 1. Upgrade the Windows Agent to version 8.2.0 or above. 2. Apply a new RME rule. For additional details, please see this knowledge base article https://support.fortra.com/endpoint-dlp/kb-articles/dg-support-notice-security-bypass-vulnerability-with-rme-MTQwYTM5NTctZDk4Ny1lZjExLWFjMjEtNjA0NWJkMDFhMzQ3 .


Workaround

No workaround given by the vendor.

History

Fri, 15 Nov 2024 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 20:15:00 +0000

Type Values Removed Values Added
Description A security bypass vulnerability exists in the Removable Media Encryption (RME)component of Digital Guardian Windows Agents prior to version 8.2.0. This allows a user to circumvent encryption controls by modifying metadata on the USB device thereby compromising the confidentiality of the stored data.
Title USB Security Feature Bypass in Digital Guardian Windows Agent Prior to version 8.2.0
Weaknesses CWE-922
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Fortra

Published:

Updated: 2024-11-15T21:11:54.745Z

Reserved: 2024-04-04T17:41:13.489Z

Link: CVE-2024-3334

cve-icon Vulnrichment

Updated: 2024-11-15T21:11:41.474Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-11-15T20:15:19.910

Modified: 2024-11-18T17:11:56.587

Link: CVE-2024-3334

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-07-12T22:01:04Z