CVE-2017-3898: Input Validation
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3898?
CVE-2017-3898 is classified as a medium severity vulnerability due to its potential for exploitation via man-in-the-middle attacks.
How do I fix CVE-2017-3898?
The recommended fix for CVE-2017-3898 is to upgrade McAfee LiveSafe to version 16.0.3 or later.
What versions of McAfee LiveSafe are affected by CVE-2017-3898?
CVE-2017-3898 affects McAfee LiveSafe versions prior to 16.0.3, specifically up to version 16.0.2.
What type of attack does CVE-2017-3898 involve?
CVE-2017-3898 involves a man-in-the-middle attack that allows attackers to modify Windows registry values.
What is the impact of CVE-2017-3898?
The impact of CVE-2017-3898 includes the potential to compromise the integrity of software updates from McAfee LiveSafe.