PT-2002-2994 · Mcafee · Mcafee Virusscan
Published
2002-12-31
·
Updated
2017-07-29
·
CVE-2002-2282
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
McAfee VirusScan version 4.5.1
Description:
The issue allows local users to run arbitrary code via malicious versions of particular DLLs when the WebScanX.exe module is enabled. This occurs because the software searches for these DLLs from the user's home directory, even when browsing the local hard drive.
Recommendations:
For McAfee VirusScan version 4.5.1, consider disabling the WebScanX.exe module until a patch is available to prevent the execution of malicious DLLs. Restrict access to the user's home directory to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mcafee Virusscan