Vulnerabilities > Mcafee > Security Scan Plus > 2.0.181.2

DATE CVE VULNERABILITY TITLE RISK
2017-09-01 CVE-2017-3897 Code Injection vulnerability in Mcafee Livesafe and Security Scan Plus
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
network
low complexity
mcafee CWE-94
7.5
2017-03-14 CVE-2016-8026 Permissions, Privileges, and Access Controls vulnerability in Mcafee Security Scan Plus 2.0.181.2
Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.
local
low complexity
mcafee CWE-264
4.6
2017-03-14 CVE-2016-8008 Permissions, Privileges, and Access Controls vulnerability in Mcafee Security Scan Plus 2.0.181.2
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.
local
low complexity
mcafee microsoft CWE-264
7.2