CVE-2016-8007
MEDIUMMcAfee Host Intrusion Prevention Services < 8.0 Patch 7 - Authenticated Registry Key Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-8007. PoCs published by dmaasland.
AI-analyzed exploit summary This is a functional Metasploit module that exploits weak registry permissions in McAfee Host Intrusion Prevention (HIP) to escalate privileges to NT AUTHORITY\SYSTEM. It manipulates registry keys to stop the HIP service, uploads a payload, and restarts the service to execute the payload with elevated privileges.
Description
Authentication bypass vulnerability in McAfee Host Intrusion Prevention Services (HIPS) 8.0 Patch 7 and earlier allows authenticated users to manipulate the product's registry keys via specific conditions.
Exploits (1)
This is a functional Metasploit module that exploits weak registry permissions in McAfee Host Intrusion Prevention (HIP) to escalate privileges to NT AUTHORITY\SYSTEM. It manipulates registry keys to stop the HIP service, uploads a payload, and restarts the service to execute the payload with elevated privileges.
References (2)
Scores
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H