| Vulnerability Name: | CVE-2016-4534 (CCN-112938) | ||||||||||||
| Assigned: | 2016-05-03 | ||||||||||||
| Published: | 2016-05-03 | ||||||||||||
| Updated: | 2016-12-01 | ||||||||||||
| Summary: | The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on Windows allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles. | ||||||||||||
| CVSS v3 Severity: | 3.0 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L) 2.6 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C)
2.6 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:N/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 3.0 Low (CVSS v2 Vector: AV:L/AC:M/Au:S/C:N/I:P/A:P)
| ||||||||||||
| Vulnerability Type: | CWE-264 | ||||||||||||
| Vulnerability Consequences: | Bypass Security | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-4534 Source: MISC Type: Exploit http://packetstormsecurity.com/files/download/136089/mcafeevses-bypass.html Source: FULLDISC Type: Exploit 20160304 McAfee VirusScan Enterprise security restrictions bypass Source: SECTRACK Type: UNKNOWN 1035754 Source: XF Type: UNKNOWN mcafee-virusscan-cve20164534-sec-bypass(112938) Source: CCN Type: McAfee Security Bulletin ID: SB10158 VirusScan Enterprise update fixes protections bypass vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://kc.mcafee.com/corporate/index?page=content&id=SB10158 Source: CONFIRM Type: Vendor Advisory https://kc.mcafee.com/resources/sites/MCAFEE/content/live/PRODUCT_DOCUMENTATION/26000/PD26485/en_US/VSE_8_8_HF1123565_release_notes.pdf Source: MISC Type: Exploit https://lab.mediaservice.net/advisory/2016-01-mcafee.txt Source: EXPLOIT-DB Type: Exploit 39531 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||