CVE-2016-1715
Summary
| CVE | CVE-2016-1715 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-01-12 20:59:11 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges via a 768 syscall, which triggers a zero to be written to an arbitrary kernel memory location. |
Risk And Classification
Primary CVSS: v3.0 6.6 MEDIUM from [email protected]
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
Problem Types: CWE-189 | n/a
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 6.6 | MEDIUM | CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H |
| 2.0 | [email protected] | Primary | 5.5 | AV:L/AC:M/Au:S/C:P/I:P/A:C |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
LowUser Interaction
RequiredScope
ChangedConfidentiality
LowIntegrity
LowAvailability
HighCVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
SingleConfidentiality
PartialIntegrity
PartialAvailability
CompleteAV:L/AC:M/Au:S/C:P/I:P/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Application Control | 6.1.0 | All | All | All |
| Application | Mcafee | Application Control | 6.1.1 | All | All | All |
| Application | Mcafee | Application Control | 6.1.2 | All | All | All |
| Application | Mcafee | Application Control | 6.1.3 | All | All | All |
| Application | Mcafee | Application Control | 6.2.0 | All | All | All |
| Operating System | Microsoft | Windows | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Zero Day Initiative | af854a3a-2127-422b-91ae-364da2661108 | www.zerodayinitiative.com | |
| McAfee KnowledgeBase - Intel Security - Security Bulletin: Application Control update fixes system crash caused by certain inputs to Application Control driver API on Windows 32-bit systems | af854a3a-2127-422b-91ae-364da2661108 | kc.mcafee.com | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.