CVE-2015-8577

low
Published 2015-12-16 · Modified 2026-05-06
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses on 32-bit platforms when protecting another application, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://kc.mcafee.com/corporate/index?page=content&id=SB10142

Application impact

VendorProductVersionsFixed
mcafeevirusscan_enterprise{"endIncluding":"8.8.0"}

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.