VULNERABILITY INTELLIGENCE

CVE-2016-9867

CVSS score8.8 HIGH
EPSS probability0.39%
CISA KEVNot currently listed
Published2017-01-06
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Description

An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI driver and may achieve code execution to escalate privileges to root on ScaleIO Data Client (SDC) servers.

Weakness classification

  • nvd@nist.gov: CWE-264

Primary references