McAfee VirusScan Enterprise for Linux Security Flaws Gives Attackers Root Access

Advertisement
By Sanket Vijayasarathy | Updated: 13 December 2016 17:36 IST

McAfee has patched 10 critical vulnerabilities in its VirusScan Enterprise for Linux, reportedly six months after they were disclosed. According to security researcher Andrew Fasano from MIT Lincoln Laboratory, the vulnerabilities when chained could result in the execution of the code remotely as a root user.

"At a first glance, Intel's McAfee VirusScan Enterprise for Linux has all the best characteristics that vulnerability researchers love: it runs as root, it claims to make your machine more secure, it's not particularly popular, and it looks like it hasn't been updated in a long time," the security advisory reads. "When I noticed all these, I decided to take a look."

Fasano said that attackers could chain the flaws to compromise VirusScan Enterprise for Linux by running malicious update servers. The malicious script after chaining the vulnerabilities is then run by the root user on the victim machine.

Advertisement

The vulnerabilities have been found present from at least version 1.9.2 through version 2.0.2, which was released in April 2016.

Advertisement

Fasano originally reported the vulnerabilities in June through the US computer emergency response team clearing house which passed on the information to McAfee. The security company in return asked for a six month non-disclosure extension until December. The company made no contact after July and was informed on December 5 that the report would be published on December 12.

McAfee on December 9 published the reports of the vulnerabilities, four days ahead of Fasano's report.

Advertisement

Fasano detailed the process which requires four of the 10 vulnerabilities to complete the exploit. The first pair, CVE-2016-8016 and CVE-2016-8017 allows an authentication token to be brute-forced and used to connect with McAfee Linux clients.

The attackers then use another flaw CVE-2016-8021 to force the target to create a malicious script. A request is then sent to authenticate the start of virus scan but which will execute the malicious script instead using CVE-2016-8020 and CVE-2016-8021. With these flaws combined, the attackers malicious script is run as root on the victim's machine.

Advertisement

In addition to this, Fasano found six more bugs which include an authenticated SQL injection, CVE-2016-8025, HTTP response splitting (CVE-2016-8024), cross-site scripting (CVE-2016-8019), cross-site request forgery tokens (CVE-2016-8018) and a remote unauthenticated file read and existence test (CVE-2016-8016, CVE-2016-8017).

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Realme Narzo 90 Series With 7,000mAh Battery Launched in India: See Pricing
  2. Realme 16 Pro to Launch With Urban Wild Design in These Four Colourways
  3. Pixel 10 Series Gets Price Cuts During Google's End of Year Sale: See Offers
  4. Lenovo Idea Tab Plus Launched in India With 10,200mah Battery: Details
  5. Vivo S50, S50 Pro Mini With Snapdragon Chips Launched at These Prices
  6. SBI YONO 2.0 Launch: State Bank of India Reportedly Targets 20 Crore Users
  7. Motorola Edge 70 First Impressions
  8. Gaming-Focused OnePlus Turbo Series Confirmed to Launch Soon
  9. Dhruv64: India's First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  10. iOS 26 Leaked Code Hints at These New Devices and Software Features
  1. Dhruv64: India’s First Homegrown 64-Bit Dual-Core Microprocessor Unveiled
  2. Disney CEO Says AI Deal With OpenAI Is Exclusive For Just One Year: Report
  3. Arasayyana Prema Prasanga Streaming Online: Know Where to Watch This Kannada Film
  4. Filmfare OTT Awards 2025 Winners: Black Warrant, Paatal Lok Season 2, Girls Will Be Girls, and More
  5. Thamma Now Streaming on Amazon Prime Video: Watch Ayushmann Khurrana and Rashmika Mandanna in This Horrer Comedy
  6. Realme 16 Pro Series Colourways Revealed; Company Announces Design Collaboration With Naoto Fukasawa
  7. Samsung Galaxy A07 5G Key Specifications Spotted in Geekbench Listing, Could Launch Soon
  8. Bungie Shares New Vision for Marathon, Confirms New March 2026 Launch Window, $40 Pricing
  9. Google to Discontinue Dark Web Reports in February 2026, Directs Users to Existing Privacy and Security Tools
  10. Realme Narzo 90 5G, Narzo 90x 5G Launched in India With 7,000mAh Battery, 50-Megapixel Cameras: Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.