Showing 2 vulnerabilities on this page for Live Safe

Signals CISA KEV Ransomware Nuclei
McAfee vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

McAfee LiveSafe 16.0.3 - Man In The Middle Registry Modification Leading to Remote Command Execution

A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.

CWE-20Sep 1, 2017
CVSS5.9v3.0EPSS3.18%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

McAfee Security Scan Plus - Remote Command Execution

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

CWE-94Sep 1, 2017
CVSS9.8v3.0EPSS11.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX