CVE-2017-3896
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.5%
exploitation probability
2.5%top 16% of all CVEs
observed exploitation
nono source reports it
In short
The McAfee Agent's remote log viewing feature doesn't properly check web link parameters, allowing attackers to send harmful input that the system doesn't validate. This could lead to unintended actions or access to sensitive information.
Technical detail
Unvalidated URL parameters in the remote log viewing functionality of McAfee Agent 5.0.x (before 5.0.4.449) permit remote attackers to inject unexpected inputs without server-side validation. The vulnerability enables parameter tampering attacks that may result in unauthorized information disclosure or system manipulation depending on how parameters are processed downstream.
Summary generated and translated by AI from the official description.
Unvalidated parameter vulnerability in the remote log viewing capability in Intel Security McAfee Agent 5.0.x versions prior to 5.0.4.449 allows remote attackers to pass unexpected input parameters via a URL that was not completely validated.
Affected products
Intel · McAfee Agent