CVE-2017-4054: McAfee Advanced Threat Defense
High severity, CVSS 8.8. EPSS: 2.6% chance of exploitation in the next 30 days.
Command Injection vulnerability in the web interface in McAfee Advanced Threat Defense (ATD) 3.10, 3.8, 3.6, 3.4 allows remote authenticated users to execute a command of their choice via a crafted HTTP request parameter.
Affected products
- McAfee Advanced Threat Defense: version 3.4 only; version 3.6 only; version 3.8 only; version 3.10 only
Published 2017-07-12. Last modified 2026-06-17.