PT-2007-2648 · Mcafee · Mcafee Virusscan For Mac

Kevin Finisterre

·

Published

2007-03-02

·

Updated

2018-10-16

·

CVE-2007-1227

CVSS v2.0

6.6

Medium

VectorAV:L/AC:M/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee VirusScan for Mac (Virex) versions prior to 7.7 patch 1
Description The issue allows local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt. This can be exploited to execute arbitrary commands, for example, by symlinking to the root crontab file.
Recommendations For versions prior to 7.7 patch 1, update to version 7.7 patch 1 or later to resolve the issue. As a temporary workaround, consider restricting access to the VShieldExclude.txt file to prevent symlink attacks until a patch is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-1227

Affected Products

Mcafee Virusscan For Mac