Exploitation Summary
EIP tracks 1 public exploit for CVE-2017-3898. PoCs published by SecuriTeam.
AI-analyzed exploit summary This exploit demonstrates a Remote Command Execution (RCE) vulnerability in McAfee LiveSafe prior to version 16.0.3 by intercepting and modifying HTTP responses to alter Windows registry values with SYSTEM privileges. The PoC uses a proxy to inject malicious registry modifications, leading to arbitrary code execution upon system restart.
Description
A man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allows network attackers to modify the Windows registry value associated with the McAfee update via the HTTP backend-response.
Exploits (1)
This exploit demonstrates a Remote Command Execution (RCE) vulnerability in McAfee LiveSafe prior to version 16.0.3 by intercepting and modifying HTTP responses to alter Windows registry values with SYSTEM privileges. The PoC uses a proxy to inject malicious registry modifications, leading to arbitrary code execution upon system restart.
References (1)
Scores
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N