CVE-2015-8577

low Trellix
CVSS v3 Base Score
2.6
AV:L/AC:H/Au:N/C:P/I:P/A:N
EPSS Score
0.0%
Exploitation probability in 30 days
Top 94% most likely to be exploited
Attack Characteristics
Attack Vector
Local
Attack Complexity
High
Confidentiality
P
Integrity
P
Availability
None
Published: December 16, 2015 (3803 days ago)
Last Modified: May 6, 2026
Vendor: Trellix
Source: NVD

Description

The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses on 32-bit platforms when protecting another application, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

CWE

CWE-264

Affected Products

mcafee virusscan enterprise

References