McAfee VirusScan Enterprise for Linux Security Flaws Gives Attackers Root Access

Advertisement
By Sanket Vijayasarathy | Updated: 13 December 2016 17:36 IST

McAfee has patched 10 critical vulnerabilities in its VirusScan Enterprise for Linux, reportedly six months after they were disclosed. According to security researcher Andrew Fasano from MIT Lincoln Laboratory, the vulnerabilities when chained could result in the execution of the code remotely as a root user.

"At a first glance, Intel's McAfee VirusScan Enterprise for Linux has all the best characteristics that vulnerability researchers love: it runs as root, it claims to make your machine more secure, it's not particularly popular, and it looks like it hasn't been updated in a long time," the security advisory reads. "When I noticed all these, I decided to take a look."

Advertisement

Fasano said that attackers could chain the flaws to compromise VirusScan Enterprise for Linux by running malicious update servers. The malicious script after chaining the vulnerabilities is then run by the root user on the victim machine.

The vulnerabilities have been found present from at least version 1.9.2 through version 2.0.2, which was released in April 2016.

Advertisement

Fasano originally reported the vulnerabilities in June through the US computer emergency response team clearing house which passed on the information to McAfee. The security company in return asked for a six month non-disclosure extension until December. The company made no contact after July and was informed on December 5 that the report would be published on December 12.

McAfee on December 9 published the reports of the vulnerabilities, four days ahead of Fasano's report.

Advertisement

Fasano detailed the process which requires four of the 10 vulnerabilities to complete the exploit. The first pair, CVE-2016-8016 and CVE-2016-8017 allows an authentication token to be brute-forced and used to connect with McAfee Linux clients.

The attackers then use another flaw CVE-2016-8021 to force the target to create a malicious script. A request is then sent to authenticate the start of virus scan but which will execute the malicious script instead using CVE-2016-8020 and CVE-2016-8021. With these flaws combined, the attackers malicious script is run as root on the victim's machine.

Advertisement

In addition to this, Fasano found six more bugs which include an authenticated SQL injection, CVE-2016-8025, HTTP response splitting (CVE-2016-8024), cross-site scripting (CVE-2016-8019), cross-site request forgery tokens (CVE-2016-8018) and a remote unauthenticated file read and existence test (CVE-2016-8016, CVE-2016-8017).

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Hikes Prices of These Tablets in India
  2. OnePlus Pad 4 to Launch in India With a 13,380mAh Battery on This Date
  3. Oppo Find X10 Key Specifications Leak as Find X9 Ultra Launch Nears
  4. Oppo Find X9 Ultra Will Go on Sale in These Storage Variants
  5. The Crew Motorfest, Horizon Zero Dawn Remastered Join Game Catalogue in April
  6. Lumio Introduces Vision 9 (2026) and Vision 7 (2026) TVs in India
  7. Xiaomi 18 Pro Leak Hints at a Dedicated Button for This Feature
  8. Motorola Razr Fold Pre-Order Listing Reveal Launch Date, Pricing, Offers
  9. Realme Buds T500 Pro Debut in India With Up to 56 Hours Total Battery Life
  10. Honor's Next Smartphone Could Pack an Even Bigger 11,000mAh Battery
  1. Adobe’s New Firefly AI Assistant Can Perform Complex Design Tasks With Text Prompts
  2. Crimson Desert Has Sold Over 5 Million Copies, Pearl Abyss Confirms
  3. UK FCA Seeks Guidance From Cryptocurrency Firms Ahead of 2027 Crypto Rules Rollout
  4. Oppo Find X10 Could Feature 8,000mAh Battery and 200-Megapixel Cameras, Tipster Claims
  5. Sambhavam Adhyayam Onnu Now Available for Streaming Online: What You Need to Know
  6. Motorola Razr Fold Launch Date Seemingly Revealed Along With Price and Offers; Pre-Orders Now Open
  7. PS Plus Game Catalogue Lineup for April Announced: The Crew Motorfest, Horizon Zero Dawn Remastered and More
  8. Bitcoin Holds Steady Near $75,000 as Cryptocurrency Prices Gain Support From Institutional Demand
  9. OnePlus Pad 4 India Launch Date Announced; Key Specifications, Design Revealed
  10. Toaster Now Streaming Online: Where to Watch Rajkummar Rao and Sanya Malhotra’s Comedy Drama?
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.