CVE-2015-8991: McAfee Cloud AV

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Malicious file execution vulnerability in Intel Security McAfee Security Scan+ (MSS+) before 3.11.266.3 allows attackers to make the product momentarily vulnerable via executing preexisting specifically crafted malware during installation or uninstallation, but not during normal operation.

Affected products

  • McAfee Cloud AV: affected versions not specified
  • McAfee Security Scan Plus: affected versions not specified
  • McAfee Security Webadvisor: version 3.7.2 only; version 4.0.1 only; version 4.0.2 only

Published 2017-03-14. Last modified 2026-06-17.