Man-in-the-Middle Attack Vulnerability in McAfee LiveSafe
CVE-2017-3898
5.9MEDIUM
Summary
A vulnerability exists in McAfee LiveSafe that allows attackers to perform man-in-the-middle attacks. This issue affects versions prior to 16.0.3 and can be exploited by network attackers to alter the Windows registry values associated with the McAfee update mechanism through manipulated HTTP backend responses, potentially compromising the integrity of the security software.
Affected Version(s)
Live Safe 16.0.3
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved