← Vulnerability feed

Vulnerability record · CVE-2016-8017 · published 14 March 2017

CVE-2016-8017: Mcafee virusscan enterprise improper input validation vulnerability

MMcafee · Virusscan Enterprise

Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.

4.1 CVSS 3.0 Medium EPSS 6.9% · top 6.1% CWE-20 · Improper input validation
4.1CVSS 3.0 base score, v2 4.0
6.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows authenticated remote attackers to read files on the webserver via a crafted user input.

CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2016-8017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-5118Mcafee virusscan enterprise vulnerabilityUntrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an uns…EPSS 1.6%8.4CVE-2020-7267Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files th…EPSS 0.26%8.4CVE-2020-7266Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete …EPSS 0.26%8.1CVE-2016-8023Mcafee virusscan enterprise improper authentication vulnerabilityAuthentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…EPSS 9.2%8.1CVE-2016-8024Mcafee virusscan enterprise vulnerabilityImproper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allow…EPSS 8.7%8.0CVE-2016-8020Mcafee virusscan enterprise code injection vulnerabilityImproper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…EPSS 11%7.9CVE-2007-2152Mcafee virusscan enterprise vulnerabilityBuffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitra…EPSS 2.6%7.8CVE-2019-3585Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow loca…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2016-8017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.