PT-2016-4901 · Mcafee · Mcafee Application Control

Published

2016-01-08

·

Updated

2016-01-21

·

CVE-2016-1715

CVSS v3.1

6.6

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions McAfee Application Control versions 6.1.0 through 6.1.0 build 706 McAfee Application Control versions 6.1.1 through 6.1.1 build 404 McAfee Application Control versions 6.1.2 through 6.1.2 build 449 McAfee Application Control versions 6.1.3 through 6.1.3 build 441 McAfee Application Control versions 6.2.0 through 6.2.0 build 505
Description The issue allows local users to cause a denial of service or gain privileges via a specific syscall, which triggers a zero to be written to an arbitrary kernel memory location, resulting in memory corruption and system crash.
Recommendations For McAfee Application Control version 6.1.0, update to build 706 or later. For McAfee Application Control version 6.1.1, update to build 404 or later. For McAfee Application Control version 6.1.2, update to build 449 or later. For McAfee Application Control version 6.1.3, update to build 441 or later. For McAfee Application Control version 6.2.0, update to build 505 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-1715
ZDI-16-007

Affected Products

Mcafee Application Control