7.5
CVSSv2

CVE-2017-3897

Published: 01/09/2017 Updated: 06/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions before 16.0.3 and McAfee Security Scan Plus (MSS+) versions before 3.11.599.3 allows network malicious users to perform a malicious file execution via a HTTP backend-response.

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee livesafe

mcafee security scan plus

Exploits

## Vulnerability Summary The following advisory describes a Remote Code Execution found in McAfee Security Scan Plus An active network attacker could launch a man-in-the-middle attack on a plaintext-HTTP response to a client to run any residing executables with privileges of a logged in user McAfee Security Scan Plus is a free diagnostic tool th ...