CVE-2016-9867: High severity dell emc scaleio vulnerability
Published Jan 6, 2017
·Updated
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI driver and may achieve code execution to escalate privileges to root on ScaleIO Data Client (SDC) servers.
Affected Software
1 affected component
EMC ScaleIO<=2.0.1.0
Event History
Jan 6, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
DescriptionWeakness
Data Sourced
via NVD·10:59 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2016-9867?
CVE-2016-9867 is considered a high severity vulnerability due to potential privilege escalation by local attackers.
2
How do I fix CVE-2016-9867?
To fix CVE-2016-9867, upgrade EMC ScaleIO to version 2.0.1.1 or later.
3
Who is affected by CVE-2016-9867?
CVE-2016-9867 affects users running EMC ScaleIO versions prior to 2.0.1.1.
4
What kind of attacks are possible with CVE-2016-9867?
CVE-2016-9867 allows low-privileged local attackers to modify kernel memory, potentially leading to code execution and privilege escalation.
5
What software does CVE-2016-9867 impact?
CVE-2016-9867 impacts EMC ScaleIO versions up to 2.0.1.0.