PT-2000-1584 · Mcafee · Mcafee Virusscan+1
Published
2000-07-11
·
Updated
2017-10-10
·
CVE-2000-0650
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
McAfee VirusScan versions 4.5
McAfee NetShield versions 4.5
Description
The issue is related to insecure permissions for a specific registry key in the default installation of the software. This allows local users to execute arbitrary commands by replacing SETUP.EXE with a malicious file, potentially leading to unauthorized access and control.
Recommendations
For McAfee VirusScan version 4.5, consider restricting access to the registry key that identifies the AutoUpgrade directory to prevent local users from replacing SETUP.EXE with a Trojan Horse.
For McAfee NetShield version 4.5, restrict access to the registry key that identifies the AutoUpgrade directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Netshield
Mcafee Virusscan