CVE-2016-3984: McAfee Active Response
Medium severity, CVSS 5.1. EPSS: 1.1% chance of exploitation in the next 30 days.
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.2 Hotfix 1110392 (5.0.2.333), Data Exchange Layer 2.x (DXL) before 2.0.1.140.1, Data Loss Prevention Endpoint (DLPe) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Device Control (MDC) 9.3 before Patch 6 and 9.4 before Patch 1 HF3, Endpoint Security (ENS) 10.x before 10.1, Host Intrusion Prevention Service (IPS) 8.0 before 8.0.0.3624, and VirusScan Enterprise (VSE) 8.8 before P7 (8.8.0.1528) on Windows allows local administrators to bypass intended self-protection rules and disable the antivirus engine by modifying registry keys.
Affected products
- McAfee Active Response: up to and including 1.1.0.158
- McAfee Agent: up to and including 5.0.2.285
- McAfee Data Exchange Layer: up to and including 2.0.0.430.1
- McAfee Data Loss Prevention Endpoint: up to and including 9.3.0; up to and including 9.4.0
- McAfee Endpoint Security: up to and including 10.0.1
- McAfee Host Intrusion Prevention: up to and including 8.0.0
- McAfee Virusscan Enterprise: up to and including 8.8.0
Published 2016-04-08. Last modified 2026-06-17.