CVE-2017-4028: McAfee Anti-Virus Plus
Medium severity, CVSS 4.4. EPSS: 0.5% chance of exploitation in the next 30 days.
Maliciously misconfigured registry vulnerability in all Microsoft Windows products in McAfee consumer and corporate products allows an administrator to inject arbitrary code into a debugged McAfee process via manipulation of registry parameters.
Affected products
- McAfee Anti-Virus Plus: affected versions not specified
- McAfee Endpoint Security: version 10.2 only
- McAfee Host Intrusion Prevention: up to and including 8.0; version 8.0 only
- McAfee Internet Security: affected versions not specified
- McAfee Total Protection: affected versions not specified
- McAfee Virus Scan Enterprise: up to and including 8.8; version 8.8 only
Published 2018-04-03. Last modified 2026-06-17.