CVE-2017-4028

Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N
trellixCNA
5 MEDIUM
LOCAL
HIGH
HIGH
CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:C/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
mcafeeanti-virus_plus
-
mcafeeendpoint_security
10.2
mcafeehost_intrusion_prevention
𝑥
≤ 8.0
mcafeehost_intrusion_prevention
8.0:patch_1
mcafeehost_intrusion_prevention
8.0:patch_2
mcafeehost_intrusion_prevention
8.0:patch_3
mcafeehost_intrusion_prevention
8.0:patch_4
mcafeehost_intrusion_prevention
8.0:patch_5
mcafeehost_intrusion_prevention
8.0:patch_6
mcafeehost_intrusion_prevention
8.0:patch_7
mcafeehost_intrusion_prevention
8.0:patch_8
mcafeehost_intrusion_prevention
8.0:patch_9
mcafeeinternet_security
-
mcafeetotal_protection
-
mcafeevirus_scan_enterprise
𝑥
≤ 8.8
mcafeevirus_scan_enterprise
8.8:patch_9
𝑥
= Vulnerable software versions