CVE-2018-6703: McAfee Agent
Critical severity, CVSS 9.8. EPSS: 3.2% chance of exploitation in the next 30 days.
Use After Free in Remote logging (which is disabled by default) in McAfee McAfee Agent (MA) 5.x prior to 5.6.0 allows remote unauthenticated attackers to cause a Denial of Service and potentially a remote code execution via a specially crafted HTTP header sent to the logging service.
Affected products
- McAfee Agent: from 5.0.0, before 5.6.0 (fixed in 5.6.0)
Published 2018-12-11. Last modified 2026-06-17.