5.9
CVSSv3

CVE-2017-3898

Published: 01/09/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.9 | Impact Score: 3.6 | Exploitability Score: 2.2
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions before 16.0.3 allows network malicious users to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee livesafe

Exploits

## Vulnerabilities Summary The following advisory describes a Remote Command Execution found in McAfee McAfee LiveSafe (MLS) versions prior to 1603 The vulnerability allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response McAfee Security Scan Plus is a free diagnostic tool t ...