×
cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
AnYiSuM
Contributor
Message 1 of 4

Security Vulnerability CVE-2021-3711 for OpenSSL

This program "C:\Program Files\McAfee\WSSVPN\Bins\x64\openssl.exe" is installed on my system by product: McAfee® LiveSafe™ with version OpenSSL 1.1.1.4 and this version has critical vulnerability "CVE- 2021-3711", I don't understand why McAfee doesn't update the version.

Can I change the version myself? The file is protected by Access Protection.

See below
https://www.openssl.org/news/vulnerabilities.html/news/vulnerabilities.html (openssl.org)

3 Replies
AvinashP
McAfee Retired
McAfee Retired
Message 2 of 4

Re: Security Vulnerability CVE-2021-3711 for OpenSSL

Hi @AnYiSuM,

Kindly help us with the McAfee version installed on the device along with the operating system details.

We also request you to disable access protection and try updating the McAfee software, we request you to update us on the outcome.

Thanks,
Avinash.

Puch
Contributor
Message 3 of 4

Re: Security Vulnerability CVE-2021-3711 for OpenSSL

McAfee, are you kidding? A year later, and it is not fixed? And I cannot even paste a screenshot, you force us to type.So here it comes: McAfee LiveSafe Version 16.0 release 16.0 R50. Components: McAfee SecurityCenter build 19.20.141, VirusScan build 26.5.136. c:\program files\mcafee\wssvpn\bins\x64\openssl.exe is vulnerable (CVE-2021-3711). If you have a VPN client which checks for potential vulnerabilities, you can forget about the connection, unless you uninstall McAfee.  

MrsNachos
Contributor
Message 4 of 4

Re: Security Vulnerability CVE-2021-3711 for OpenSSL

Hello,

I have been struggling to figure out why I keep having issues with my McAfee program being manipulated and I found this post which describes the same version I had installed for McAfee.  Also, I found a second program has been installed on my computer called “WebAdvisor by McAfee” and it’s located in both program files (3 of them) and the users\username\AppData\Roaming\Microsoft\Windows\Recent\McAfee WebAdvisor(user level process).Ink. I thought I had seen something that discussed this as well as a sign of exploited vulnerability but now I can’t find that info.  Anyone know if this is correct?  I appreciate any help offered!  

How Many Badges Can You Collect?
Ready for a little competition? Members like you are earning badges and unlocking perks for their helpful answers. Are you? Click here to find out.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community