CVE-2015-8772
CRITICALMcAfee File Lock 5.x - Kernel Memory Leak or Denial of Service via IOCTL_DISK_VERIFY
Title source: llmDescription
McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large VERIFY_INFORMATION.Length value in an IOCTL_DISK_VERIFY ioctl call.
References (2)
Core 2
Core References
Mailing List mailing-list
x_refsource_fulldisc
http://seclists.org/fulldisclosure/2016/Jan/90
Various Sources x_refsource_misc
https://www.nettitude.co.uk/mcafee-file-lock-driver-kernel-memory-leak/
Scores
CVSS v3
9.1
EPSS
0.0049
EPSS Percentile
65.8%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Details
CWE
CWE-19
Status
published
Products (1)
mcafee/file_lock
5.0
Published
Jan 29, 2016
Tracked Since
Feb 18, 2026