McAfee VirusScan Enterprise for Linux Security Flaws Gives Attackers Root Access

Advertisement
By Sanket Vijayasarathy | Updated: 13 December 2016 17:36 IST

McAfee has patched 10 critical vulnerabilities in its VirusScan Enterprise for Linux, reportedly six months after they were disclosed. According to security researcher Andrew Fasano from MIT Lincoln Laboratory, the vulnerabilities when chained could result in the execution of the code remotely as a root user.

"At a first glance, Intel's McAfee VirusScan Enterprise for Linux has all the best characteristics that vulnerability researchers love: it runs as root, it claims to make your machine more secure, it's not particularly popular, and it looks like it hasn't been updated in a long time," the security advisory reads. "When I noticed all these, I decided to take a look."

Advertisement

Fasano said that attackers could chain the flaws to compromise VirusScan Enterprise for Linux by running malicious update servers. The malicious script after chaining the vulnerabilities is then run by the root user on the victim machine.

The vulnerabilities have been found present from at least version 1.9.2 through version 2.0.2, which was released in April 2016.

Advertisement

Fasano originally reported the vulnerabilities in June through the US computer emergency response team clearing house which passed on the information to McAfee. The security company in return asked for a six month non-disclosure extension until December. The company made no contact after July and was informed on December 5 that the report would be published on December 12.

McAfee on December 9 published the reports of the vulnerabilities, four days ahead of Fasano's report.

Advertisement

Fasano detailed the process which requires four of the 10 vulnerabilities to complete the exploit. The first pair, CVE-2016-8016 and CVE-2016-8017 allows an authentication token to be brute-forced and used to connect with McAfee Linux clients.

The attackers then use another flaw CVE-2016-8021 to force the target to create a malicious script. A request is then sent to authenticate the start of virus scan but which will execute the malicious script instead using CVE-2016-8020 and CVE-2016-8021. With these flaws combined, the attackers malicious script is run as root on the victim's machine.

Advertisement

In addition to this, Fasano found six more bugs which include an authenticated SQL injection, CVE-2016-8025, HTTP response splitting (CVE-2016-8024), cross-site scripting (CVE-2016-8019), cross-site request forgery tokens (CVE-2016-8018) and a remote unauthenticated file read and existence test (CVE-2016-8016, CVE-2016-8017).

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Here's Why the Google Pixel 11 Series Will Not Get GrapheneOS
  2. Ather Konarc Launched With Up to 200km Range, AEBS Braking and More
  3. Smartphones Launched in India (August 2026): See List
  4. Realme P4s vs iQOO Z11 vs Nothing Phone 4b Compared
  5. iPhone Ultra Might Not Get a Dedicated Apple Pencil Stylus
  6. iPhone Ultra Screen Replacement Could Be Costlier Than Galaxy Z Fold 8
  1. Redmi 17 5G India Launch Date Announced; Will Debut With a Larger Battery Than the Global Model
  2. Huawei Watch D3, FreeBuds Neo Launch Date Announced; Design, Key Specifications Teased
  3. Motorola Teases New Razr Foldable With Swarovski Crystal Design Ahead of IFA
  4. Google Pixel 11 Series Will Not Get GrapheneOS as Google Skips a Major Security Feature
  5. Ather Konarc Launched in India With Up to 200km IDC Range, AEBS Braking and MagicKey: Price, Features
  6. iPhone Ultra May Launch Without an Apple Pencil, New Report Claims
  7. Xiaomi 18 Fold Battery and Charging Details Leaked Ahead of Launch: What You Need to Know
  8. Apple’s Foldable iPhone Could Be Expensive to Repair, With Screen Cost Tipped at Over $1,000
  9. WhatsApp's Scam Alert Feature Arrives for Android Beta Users: Report
  10. Poco F9 Ultra May Cost Nearly Twice as Much as Poco F9 Pro, Tipster Claims
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.