A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
📦
livesafe
Vendor: mcafee
Actively Exploited
0
CISA KEV List
PoC / Exploits
3
Code Available
Total RCEs
1
Remote Access
Total CVEs
39
Total Indexed
Avg. EPSS
8.20%
Exploit Prob.
Security Vulnerability Index
Page 1 / 4
5.9
CVSS
CVE-2017-3898
Exploit Found
Severity: MEDIUM
9.8
CVSS
CVE-2017-3897
RCE
Exploit Found
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
Severity: CRITICAL
7.5
CVSS
CVE-2016-4535
Exploit Found
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (memory corruption and crash) via a crafted packed executable.
Severity: HIGH