Improper Signature Verification in Intel Security VirusScan Enterprise Linux
CVE-2016-8021

5MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
14 March 2017

Badges

๐Ÿ‘พ Exploit Exists

What is CVE-2016-8021?

The vulnerability found in Intel Security VirusScan Enterprise Linux (VSEL) versions 2.0.3 and earlier allows remote authenticated users to exploit improper verification of cryptographic signatures. By utilizing a specially crafted input file, attackers can spoof the update server and execute arbitrary code on the affected systems, potentially compromising data integrity and system security.

Affected Version(s)

VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.