CVE-2017-3897

critical
Published 2017-09-01 · Modified 2026-05-13
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secure@intel.com — http://service.mcafee.com/FAQDocument.aspx?lc=1033&id=TS102723

Application impact

VendorProductVersionsFixed
mcafeelivesafe{"endIncluding":"16.0.2"}
mcafeesecurity_scan_plus{"endIncluding":"3.11.599.2"}

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.