VULNERABILITY INTELLIGENCE
CVE-2016-9867
CVSS score8.8 HIGH
EPSS probability0.39%
CISA KEVNot currently listed
Published2017-01-06
Last modified2026-06-17
CVSS vectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may be able to modify the kernel memory in the SCINI driver and may achieve code execution to escalate privileges to root on ScaleIO Data Client (SDC) servers.
Weakness classification
- nvd@nist.gov: CWE-264
Primary references
- security_alert@emc.com — Third Party Advisory, VDB Entry
- security_alert@emc.com
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry
- af854a3a-2127-422b-91ae-364da2661108