First published: Fri Jan 06 2017(Updated: )
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI driver and may achieve code execution to escalate privileges to root on ScaleIO Data Client (SDC) servers.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Dell EMC ScaleIO | <=2.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-9867 is considered a high severity vulnerability due to potential privilege escalation by local attackers.
To fix CVE-2016-9867, upgrade EMC ScaleIO to version 2.0.1.1 or later.
CVE-2016-9867 affects users running EMC ScaleIO versions prior to 2.0.1.1.
CVE-2016-9867 allows low-privileged local attackers to modify kernel memory, potentially leading to code execution and privilege escalation.
CVE-2016-9867 impacts EMC ScaleIO versions up to 2.0.1.0.