First published: Fri Apr 08 2016(Updated: )
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Active Response | <=1.1.0.158 | |
Mcafee Agent | <=5.0.2.285 | |
McAfee Data eXchange Layer | <=2.0.0.430.1 | |
Mcafee Data Loss Prevention Endpoint | <=9.3.0 | |
Mcafee Data Loss Prevention Endpoint | <=9.4.0 | |
Mcafee Endpoint Security | <=10.0.1 | |
Mcafee Host Intrusion Prevention | <=8.0.0 | |
Mcafee Virusscan Enterprise | <=8.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.