CVE-2017-3897
Description
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
In plain language
AI Worth attentionCVE-2017-3897 is a code-injection bug in McAfee Live Safe and McAfee Security Scan Plus that a remote attacker may be able to use without any log-in; small businesses should update to the fixed versions as soon as possible.
CVE-2017-3897 is a code injection (CWE-94) in the non-certificate-based authentication mechanism for McAfee Live Safe and McAfee Security Scan Plus, where a network attacker can trigger malicious file execution via an HTTP backend response; patching is the only confirmed mitigation because exploitation isn’t evidenced in the provided findings.
What to do now
- Check whether your business uses McAfee Live Safe or McAfee Security Scan Plus (MSS+), and note the installed versions.
- If you are on McAfee Live Safe earlier than 16.0.3, plan an upgrade to 16.0.3.
- If you are on McAfee Security Scan Plus earlier than 3.11.599.3, plan an upgrade to 3.11.599.3.
- If you cannot upgrade immediately, isolate the affected machines from unnecessary inbound network access until the update is applied.
- Confirm after upgrading that the application reports the new version and that your security tool is functioning normally.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2017-3897 and every CVE in our database. Create a free account — no credit card required.
Create Free Account