Advanced Threat Defense (ATD) - Unprotected storage of shared credentials vulnerability
CVE-2019-3663
Key Information
- Vendor
- Mcafee
- Status
- Advanced Threat Defense (atd)
- Vendor
- CVE Published:
- 14 November 2019
Badges
Summary
Unprotected Storage of Credentials vulnerability in McAfee Advanced Threat Defense (ATD) prior to 4.8 allows local attacker to gain access to the root password via accessing sensitive files on the system. This was originally published with a CVSS rating of High, further investigation has resulted in this being updated to Critical. The root password is common across all instances of ATD prior to 4.8. See the Security bulletin for further details
Affected Version(s)
Advanced Threat Defense (ATD) = prior to 4.8
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- π‘
Public PoC available
- πΎ
Exploit known to exist
Vulnerability published
Vulnerability Reserved