CVE-2016-3984

MEDIUM

McAfee - Multiple Vulns

Title source: llm

Description

The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.

Exploits (1)

exploitdb WORKING POC
by Maurizio Agazzini · clocalwindows
https://www.exploit-db.com/exploits/39531

Scores

CVSS v3 5.1
EPSS 0.0029
EPSS Percentile 52.1%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H

Classification

CWE
CWE-284
Status draft

Affected Products (8)

mcafee/active_response < 1.1.0.158
mcafee/agent < 5.0.2.285
mcafee/data_exchange_layer < 2.0.0.430.1
mcafee/data_loss_prevention_endpoint < 9.3.0
mcafee/data_loss_prevention_endpoint < 9.4.0
mcafee/endpoint_security < 10.0.1
mcafee/host_intrusion_prevention < 8.0.0
mcafee/virusscan_enterprise < 8.8.0

Timeline

Published Apr 08, 2016
Tracked Since Feb 18, 2026