PT-2001-1167 · Mcafee · Mcafee Virusscan
Publicado
2001-01-09
·
Atualizado
2008-09-05
·
CVE-2000-1128
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
McAfee VirusScan version 4.5
Description
The default configuration of the software does not properly quote the
ImagePath variable, which sets the search path incorrectly. This allows local users to place a Trojan horse program, such as "common.exe", in the C:Program Files directory.Recommendations
For McAfee VirusScan version 4.5, consider quoting the
ImagePath variable to properly set the search path and prevent local users from placing malicious programs in the C:Program Files directory. As a temporary workaround, restrict access to the C:Program Files directory to minimize the risk of exploitation.Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mcafee Virusscan