LiveActive security incident?Get immediate response
CVE Record

CVE-2016-8011: Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2...

Cross-site scripting vulnerability in Intel Security McAfee Endpoint Security (ENS) Web Control before 10.2.0.408.10 allows attackers to inject arbitrary web script or HTML via a crafted web site.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysisunknown

Security readout for executives and security teams

Plain-English summary

McAfee Endpoint Security Web Control had a cross-site scripting flaw before version 10.2.0.408.10. A malicious website could inject script or HTML into the product’s browsing-protection context. The source bundle does not provide severity, CVSS, exploit maturity, or detailed impact evidence.

Executive priority

Handle as a targeted hygiene update, not a confirmed emergency. Prioritize if legacy McAfee ENS Web Control remains deployed, especially on endpoints exposed to routine web browsing.

Technical view

CVE-2016-8011 affects Intel Security McAfee Endpoint Security (ENS) Web Control versions before 10.2.0.408.10. The described input vector is a crafted website that enables arbitrary web script or HTML injection. The sources do not include CWE, CVSS, detailed attack prerequisites, or vendor remediation text beyond the affected-version boundary.

Likely exposure

Exposure is limited to environments running McAfee ENS Web Control before 10.2.0.408.10. Risk depends on whether the Web Control component is installed, enabled, and used by endpoints that browse attacker-controlled or compromised websites.

Exploitation context

The CVE describes exploitation through a crafted website. The bundle says KEV is false and provides no cited evidence of active exploitation, public exploit availability, or exploitation complexity. Treat exploitation status as unconfirmed.

Researcher notes

Evidence is sparse: the public record names the affected product, version boundary, and XSS vector, but omits CVSS, CWE, detailed root cause, and exploit status. Avoid assuming broader McAfee product impact without vendor confirmation.

Mitigation direction

  • Inventory ENS Web Control installations and identify versions before 10.2.0.408.10.
  • Upgrade affected deployments to 10.2.0.408.10 or later, following vendor guidance.
  • If immediate upgrade is unavailable, review vendor advisory SB10180 for supported mitigations.
  • Prioritize endpoints used for general web browsing or high-risk user groups.

Validation and detection

  • Confirm whether ENS Web Control is installed and enabled on managed endpoints.
  • Check installed product versions against the affected range: before 10.2.0.408.10.
  • Review endpoint management records for successful upgrade or remediation completion.
  • Monitor security advisories for any later exploitation or remediation updates.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2016-8011 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
IntelMcAfee Endpoint Security (ENS) Web Controlbefore 10.2.0.408.10Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.