Vulnerability CVE-2012-5879


Published: 2013-03-28   Modified: 2013-03-29

Description:
An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or create arbitrary files via a full pathname argument to the Save method.

See advisories in our WLB2 database:
Topic
Author
Date
High
McAfee Virtual Technician (MVT) 6.5.0.2101 Unsafe Active-X
High-Tech Bridge...
28.03.2013

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

CVSS2 => (AV:N/AC:M/Au:S/C:C/I:C/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
8.2/10
9.5/10
6.8/10
Exploit range
Attack complexity
Authentication
Remote
Medium
Single time
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Partial
Affected software
Mcafee -> Epo mcafee virtual technician 
Mcafee -> Mcafee virtual technician 

 References:
https://www.htbridge.com/advisory/HTB23128
https://kc.mcafee.com/corporate/index?page=content&id=SB10040
http://www.securitytracker.com/id/1028357
http://www.securityfocus.com/bid/58750
http://osvdb.org/91700
http://archives.neohapsis.com/archives/bugtraq/2013-03/0143.html

Copyright 2024, cxsecurity.com

 

Back to Top