Vulnerability Description
McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large VERIFY_INFORMATION.Length value in an IOCTL_DISK_VERIFY ioctl call.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | File Lock | 5.0 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2016/Jan/90
- https://www.nettitude.co.uk/mcafee-file-lock-driver-kernel-memory-leak/
- http://seclists.org/fulldisclosure/2016/Jan/90
- https://www.nettitude.co.uk/mcafee-file-lock-driver-kernel-memory-leak/
FAQ
What is CVE-2015-8772?
CVE-2015-8772 is a vulnerability with a CVSS score of 9.1 (CRITICAL). McPvDrv.sys 4.6.111.0 in McAfee File Lock 5.x in McAfee Total Protection allows local users to obtain sensitive information from kernel memory or cause a denial of service (system crash) via a large V...
How severe is CVE-2015-8772?
CVE-2015-8772 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2015-8772?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee File Lock.