vendor:
VirusScan Enterprise
by:
SecurityFocus
7.2
CVSS
HIGH
Arbitrary File Execution
78
CWE
Product Name: VirusScan Enterprise
Affected Version From: 8.0i (patch 11)
Affected Version To: 8.0i (patch 11)
Patch Exists: Yes
Related CWE: N/A
CPE: a:mcafee:virusscan_enterprise
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
McAfee VirusScan Arbitrary File Execution Vulnerability
McAfee VirusScan is prone to a vulnerability that could allow an arbitrary file to be executed. The 'naPrdMgr.exe' process calls applications without using properly quoted paths. Successful exploitation may allow local attackers to gain elevated privileges.
Mitigation:
Update to the latest version of McAfee VirusScan.