PT-2002-2994 · Mcafee · Mcafee Virusscan

Published

2002-12-31

·

Updated

2017-07-29

·

CVE-2002-2282

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: McAfee VirusScan version 4.5.1
Description: The issue allows local users to run arbitrary code via malicious versions of particular DLLs when the WebScanX.exe module is enabled. This occurs because the software searches for these DLLs from the user's home directory, even when browsing the local hard drive.
Recommendations: For McAfee VirusScan version 4.5.1, consider disabling the WebScanX.exe module until a patch is available to prevent the execution of malicious DLLs. Restrict access to the user's home directory to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2282

Affected Products

Mcafee Virusscan