vendor:
McAfee Virtual Technician (MVT)
by:
High-Tech Bridge Security Research Lab
5,8
CVSS
MEDIUM
Exposed Unsafe ActiveX Method
618
CWE
Product Name: McAfee Virtual Technician (MVT)
Affected Version From: 6.5.0.2101
Affected Version To: 6.5.0.2101
Patch Exists: YES
Related CWE: CVE-2012-5879
CPE: a:mcafee:virtual_technician:6.5.0.2101
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 SP1 and Internet Explorer 9
2013
Insecure method in McAfee Virtual Technician ActiveX control
The vulnerability exists due to the ActiveX control including the insecure "Save()" method in "McHealthCheck.dll" DLL. This can be exploited to corrupt or create arbitrary files in the context of the current user.
Mitigation:
Upgrade to McAfee Virtual Techinician 6.5.0.2102 or later.