
Cloud Vulnerability DB
A community-led vulnerabilities database
A stored cross-site scripting (XSS) vulnerability identified as CVE-2021-23881 was discovered in the ePO extension of McAfee Endpoint Security (ENS) prior to version 10.7.0 February 2021 Update. The vulnerability was disclosed in February 2021 and affects the McAfee ENS ePO extension (NVD, CVE Mitre).
The vulnerability is classified as CWE-79 (Cross-site Scripting) and allows an ENS ePO administrator to add a script to a policy event. When a local non-administrator user triggers the policy, the script is executed through a browser block page (NVD).
When exploited, this vulnerability enables the execution of arbitrary web scripts or HTML through the browser block page when a local non-administrator user triggers the policy. This could potentially lead to unauthorized access to sensitive information or manipulation of the user's browser session (CVE Mitre).
The vulnerability requires an ENS ePO administrator account to add the malicious script to a policy event. The execution of the script is triggered when a local non-administrator user encounters the policy violation (NVD).
The vulnerability was addressed in McAfee Endpoint Security (ENS) version 10.7.0 February 2021 Update. Users are advised to upgrade to this version or later to mitigate the risk (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."