CVE-2019-3621
MEDIUM 6.8EPSS 0.3%
Authentication protection bypass vulnerability in McAfee Data Loss Prevention (DLPe) for Windows 11.x prior to 11.3.0 allows physical local user to bypass the Windows lock screen via DLPe processes being killed just prior to the screen being locked or when the screen is locked. The attacker requires physical access to the machine.
- CVSS v3.0
- 6.2 MEDIUM
CVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - CVSS v3.0
- 6.8 MEDIUM
CVSS:3.0/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H - CVSS v2.0
- 4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 0.35% chance of exploitation in the next 30 days, 28th percentile
- Published
- 2019-07-25
- Updated
- 2024-08-04
Proof-of-concept exploits (1)
- sjl-is-big-idiot/loophole-demo0★ · 2021-04-19