CVE-2016-1715
Last modified
CVE-2016-1715 is a vulnerability of currently unknown severity. The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges via a 768 syscall, which triggers a zero to be written to an arbitrary kernel memory location.. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
The swin.sys kernel driver in McAfee Application Control (MAC) 6.1.0 before build 706, 6.1.1 before build 404, 6.1.2 before build 449, 6.1.3 before build 441, and 6.2.0 before build 505 on 32-bit Windows platforms allows local users to cause a denial of service (memory corruption and system crash) or gain privileges via a 768 syscall, which triggers a zero to be written to an arbitrary kernel memory location.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Windows | All versions |
| Mcafee | Application Control | 6.1.0 |
| Mcafee | Application Control | 6.1.1 |
| Mcafee | Application Control | 6.1.2 |
| Mcafee | Application Control | 6.1.3 |
| Mcafee | Application Control | 6.2.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-1715?
How severe is CVE-2016-1715?
How do I fix CVE-2016-1715?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2016
- CVE-2016-1709Heap-based buffer overflow in the ByteArray::Get method in d…
- CVE-2016-1710The ChromeClientImpl::createWindow method in WebKit/Source/w…
- CVE-2016-1711WebKit/Source/core/loader/FrameLoader.cpp in Blink, as used …
- CVE-2016-1712Palo Alto Networks PAN-OS before 5.0.19, 5.1.x before 5.1.12…
- CVE-2016-1713Unrestricted file upload vulnerability in the Settings_Vtige…
- CVE-2016-1714The (1) fw_cfg_write and (2) fw_cfg_read functions in hw/nvr…
- CVE-2016-1716AppleGraphicsPowerManagement in Apple OS X before 10.11.3 al…
- CVE-2016-1717The Disk Images component in Apple iOS before 9.2.1, OS X be…
- CVE-2016-1718The IOAcceleratorFamily2 interface in IOAcceleratorFamily in…
- CVE-2016-1719The IOHIDFamily API in Apple iOS before 9.2.1, OS X before 1…
- CVE-2016-1720IOKit in Apple iOS before 9.2.1, OS X before 10.11.3, and tv…
- CVE-2016-1721The kernel in Apple iOS before 9.2.1, OS X before 10.11.3, a…
Are you affected by CVE-2016-1715?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
