First published: Tue Mar 14 2017(Updated: )
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Security Scan Plus | <=3.11.376 | |
Microsoft Windows 10 | ||
Microsoft Windows 7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-8008 is classified as a privilege escalation vulnerability that can potentially allow attackers to gain elevated access to system resources.
To fix CVE-2016-8008, users should update McAfee Security Scan Plus to the latest version beyond 3.11.376.
CVE-2016-8008 affects Windows 7 and Windows 10 systems that have McAfee Security Scan Plus version 3.11.376 or earlier installed.
CVE-2016-8008 requires local access to exploit the vulnerability, as it involves loading a malicious version.dll file via McAfee McUICnt.exe.
Exploitation of CVE-2016-8008 can lead to unauthorized privilege escalation, allowing attackers to execute arbitrary code with elevated permissions.