SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-4028

Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.

MEDIUM 4.4EPSS 0.53%

Does this matter?

Lower severity and a low EPSS score (0.53%). Track it; it rarely justifies an emergency change on its own.

Description

Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.

CVSS 3.0
4.4 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
EPSS
0.53% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-74
Affected
mcafee/anti-virus plus · mcafee/endpoint security · mcafee/host intrusion prevention · mcafee/internet security · mcafee/total protection · mcafee/virus scan enterprise
Source
trellixpsirt@trellix.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.