CVE-2017-4053: OS Command Injection
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote unauthenticated users / remote attackers to execute a command of their choice via a crafted HTTP request parameter.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4053?
CVE-2017-4053 is rated as a high severity vulnerability due to its potential for remote command execution by unauthenticated attackers.
How do I fix CVE-2017-4053?
To fix CVE-2017-4053, update McAfee Advanced Threat Defense to the latest version that contains security patches addressing this vulnerability.
What impact does CVE-2017-4053 have on affected systems?
The impact of CVE-2017-4053 allows attackers to execute arbitrary commands on the affected McAfee Advanced Threat Defense systems.
Is CVE-2017-4053 exploitable without authentication?
Yes, CVE-2017-4053 is exploitable without authentication, making it particularly dangerous.
What versions of McAfee Advanced Threat Defense are affected by CVE-2017-4053?
CVE-2017-4053 affects McAfee Advanced Threat Defense versions 3.4, 3.6, 3.8, and 3.10.