CVE-2016-3984
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch…
Does this matter?
Lower severity and a low EPSS score (1.13%). Track it; it rarely justifies an emergency change on its own.
Description
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
- CVSS 3.0
- 5.1 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
- EPSS
- 1.13% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Affected
- mcafee/active response · mcafee/agent · mcafee/data exchange layer · mcafee/data loss prevention endpoint · mcafee/endpoint security · mcafee/host intrusion prevention · mcafee/virusscan enterprise
- Source
- cve@mitre.org
References
- http://lab.mediaservice.net/advisory/2016-01-mcafee.txtExploit
- http://seclists.org/fulldisclosure/2016/Mar/13
- http://www.securitytracker.com/id/1035130
- https://kc.mcafee.com/corporate/index?page=content&id=SB10151Vendor Advisory
- https://www.exploit-db.com/exploits/39531/Exploit
- http://lab.mediaservice.net/advisory/2016-01-mcafee.txtExploit
- http://seclists.org/fulldisclosure/2016/Mar/13
- http://www.securitytracker.com/id/1035130
- https://kc.mcafee.com/corporate/index?page=content&id=SB10151Vendor Advisory
- https://www.exploit-db.com/exploits/39531/Exploit
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.