McAfee Application Control 6.x < 6.2.0.567 / 7.0.x < 7.0.1.275 Unauthorized IOCTL Use Local Privilege Escalation (SB10175)

high Nessus Plugin ID 95924

Synopsis

The remote host has a security application installed that is affected by a local privilege escalation vulnerability.

Description

The version of McAfee Application Control (MAC) installed on the remote Windows host is 6.x prior to 6.2.0 build 567 or 7.0.x prior to 7.0.1 build 275. It is, therefore, affected by a local privilege escalation vulnerability due to the unauthorized use of IOCTL. A local attacker can exploit this to gain elevated privileges.

Solution

Upgrade to McAfee Application Control version 6.2.0.567 / 7.0.1.275 or later as referenced in the vendor advisory.

See Also

https://kc.mcafee.com/corporate/index?page=content&id=SB10175

Plugin Details

Severity: High

ID: 95924

File Name: mcafee_app_ctl_7_0_1_275.nasl

Version: 1.4

Type: local

Agent: windows

Family: Windows

Published: 12/16/2016

Updated: 11/13/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: Medium

Base Score: 4.6

Temporal Score: 3.4

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2016-8009

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:mcafee:application_control

Required KB Items: installed_sw/McAfee Application Control

Exploit Ease: No known exploits are available

Patch Publication Date: 10/14/2015

Vulnerability Publication Date: 11/22/2016

Reference Information

CVE: CVE-2016-8009

MCAFEE-SB: SB10175