PT-2011-4245 · Mcafee · Mcafee Saas Endpoint Protection
Published
2011-08-10
·
Updated
2017-08-29
·
CVE-2011-3007
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
McAfee SaaS Endpoint Protection versions 5.2.1 and earlier
Description
The issue allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the
MyCioScan.Scan.ReportFile parameter. This can be used to inject script into a log file and execute arbitrary code using the MyCioScan.Scan.Start method.Recommendations
For McAfee SaaS Endpoint Protection versions 5.2.1 and earlier, consider restricting access to the
MyCioScan.Scan.ReportFile parameter to prevent arbitrary file writing. As a temporary workaround, avoid using the MyCioScan.Scan.Start method until a fix is available.Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mcafee Saas Endpoint Protection