← Vulnerability feed

Vulnerability record · CVE-2016-8008 · published 14 March 2017

CVE-2016-8008: Mcafee security scan plus permissions and access controls vulnerability

MMcafee · Security Scan Plus

Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.

8.8 CVSS 3.0 High EPSS 0.37% · top 71.7% CWE-264 · Permissions and access controls
8.8CVSS 3.0 base score, v2 7.2
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Privilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of the version.dll file via McAfee McUICnt.exe onto a Windows system.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8008 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-3897Mcafee livesafe code injection vulnerabilityA Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security…EPSS 12%7.8CVE-2022-37025Mcafee security scan plus improper privilege management vulnerabilityAn improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuratio…EPSS 0.21%7.8CVE-2016-8026Mcafee security scan plus permissions and access controls vulnerabilityArbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain e…EPSS 0.44%7.0CVE-2015-8991Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security McAfee Security Scan+ (MSS+) before 3.11.266.3 allows attackers to make the product momentar…EPSS 0.31%7.0CVE-2015-8992Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security WebAdvisor before 4.0.2, 4.0.1 and 3.7.2 allows attackers to make the product momentarily vu…EPSS 0.31%7.0CVE-2015-8993Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security CloudAV (Beta) before 0.5.0.151.3 allows attackers to make the product momentarily vulnerabl…EPSS 0.31%5.1CVE-2015-3246libuser userhelper direct /etc/passwd write race conditionlibuser before 0.56.13-8 and 0.60 before 0.60-7, as used by the userhelper program in the usermode package, modifies /etc/passwd directly instead of …KEVEPSS 8.8%analysed6.6CVE-2015-1769Windows Mount Manager symlink mishandling allows local privilege escalationThe Windows Mount Manager mishandles symbolic links, allowing a crafted USB device to trigger arbitrary code execution. Because the flaw is in a core…KEVEPSS 4.1%analysed

Source: NIST National Vulnerability Database (record CVE-2016-8008), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.