PT-2016-6008 · Microsoft+1 · Windows+1

Maurizio Agazzini

·

Published

2016-05-05

·

Updated

2016-12-01

·

CVE-2016-4534

CVSS v2.0

3.0

Low

VectorAV:L/AC:M/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions McAfee VirusScan Enterprise version 8.8.0 before Hotfix 1123565 (8.8.0.1546)
Description The issue allows local administrators to bypass intended self-protection rules and unlock the console window by closing registry handles. This is related to the McAfee VirusScan Console (mcconsol.exe) on Windows.
Recommendations For McAfee VirusScan Enterprise version 8.8.0 before Hotfix 1123565 (8.8.0.1546), apply Hotfix 1123565 (8.8.0.1546) to resolve the issue. As a temporary workaround, consider restricting access to the registry handles related to the McAfee VirusScan Console to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-4534

Affected Products

Mcafee Virusscan Enterprise
Windows