First published: Fri Sep 01 2017(Updated: )
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee LiveSafe | <=16.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3898 is classified as a medium severity vulnerability due to its potential for exploitation via man-in-the-middle attacks.
The recommended fix for CVE-2017-3898 is to upgrade McAfee LiveSafe to version 16.0.3 or later.
CVE-2017-3898 affects McAfee LiveSafe versions prior to 16.0.3, specifically up to version 16.0.2.
CVE-2017-3898 involves a man-in-the-middle attack that allows attackers to modify Windows registry values.
The impact of CVE-2017-3898 includes the potential to compromise the integrity of software updates from McAfee LiveSafe.