Vulnerabilities > Mcafee > Security Scan Plus > 3.11.376

DATE CVE VULNERABILITY TITLE RISK
2022-08-18 CVE-2022-37025 Improper Privilege Management vulnerability in Mcafee Security Scan Plus
An improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuration file and perform a LOLBin (Living off the land) attack.
local
low complexity
mcafee CWE-269
7.8
2017-09-01 CVE-2017-3897 Code Injection vulnerability in Mcafee Livesafe and Security Scan Plus
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.
network
low complexity
mcafee CWE-94
critical
9.8
2017-03-14 CVE-2016-8026 Permissions, Privileges, and Access Controls vulnerability in Mcafee Security Scan Plus 2.0.181.2/3.11.376/3.11.469
Arbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain elevated privileges via unspecified vectors.
local
low complexity
mcafee CWE-264
7.8
2017-03-14 CVE-2016-8008 Permissions, Privileges, and Access Controls vulnerability in Mcafee Security Scan Plus 2.0.181.2/3.11.376
Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.
local
low complexity
mcafee CWE-264
8.8