5.6
CVE-2019-3610
- EPSS 0.05%
- Veröffentlicht 13.02.2019 17:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:14
- Quelle trellixpsirt@trellix.com
- CVE-Watchlists
- Unerledigt
True Key Browser Extension 3.1.9219.0 update fixes Sensitive Data Exposure vulnerability
Data Leakage Attacks vulnerability in Microsoft Windows client in McAfee True Key (TK) 3.1.9211.0 and earlier allows local users to expose confidential data via specially crafted malware.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.05% | 0.109 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
| nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| trellixpsirt@trellix.com | 5.6 | 1.1 | 4 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.