← Vulnerability feed

Vulnerability record · CVE-2017-3897 · published 1 September 2017

CVE-2017-3897: Mcafee livesafe code injection vulnerability

MMcafee · Livesafe

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

9.8 CVSS 3.0 Critical EPSS 12% · top 4.1% CWE-94 · Code injection
9.8CVSS 3.0 base score, v2 7.5
12%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-3897 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2016-8008Mcafee security scan plus permissions and access controls vulnerabilityPrivilege escalation vulnerability in Windows 7 and Windows 10 in McAfee Security Scan Plus (SSP) 3.11.376 allows attackers to load a replacement of …EPSS 0.37%7.8CVE-2022-37025Mcafee security scan plus improper privilege management vulnerabilityAn improper privilege management vulnerability in McAfee Security Scan Plus (MSS+) before 4.1.262.1 could allow a local user to modify a configuratio…EPSS 0.21%7.8CVE-2016-8026Mcafee security scan plus permissions and access controls vulnerabilityArbitrary command execution vulnerability in Intel Security McAfee Security Scan Plus (SSP) 3.11.469 and earlier allows authenticated users to gain e…EPSS 0.44%7.5CVE-2016-4535Mcafee livesafe improper input validation vulnerabilityInteger signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to cause a denial of service (mem…EPSS 9.8%7.0CVE-2015-8991Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security McAfee Security Scan+ (MSS+) before 3.11.266.3 allows attackers to make the product momentar…EPSS 0.31%7.0CVE-2015-8992Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security WebAdvisor before 4.0.2, 4.0.1 and 3.7.2 allows attackers to make the product momentarily vu…EPSS 0.31%7.0CVE-2015-8993Mcafee security webadvisor permissions and access controls vulnerabilityMalicious file execution vulnerability in Intel Security CloudAV (Beta) before 0.5.0.151.3 allows attackers to make the product momentarily vulnerabl…EPSS 0.31%5.9CVE-2017-3898Mcafee livesafe improper input validation vulnerabilityA man-in-the-middle attack vulnerability in the non-certificate-based authentication mechanism in McAfee LiveSafe (MLS) versions prior to 16.0.3 allo…EPSS 3.2%

Source: NIST National Vulnerability Database (record CVE-2017-3897), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.