vendor:
McAfee Virtual Technician
by:
7.5
CVSS
HIGH
Security Bypass Remote Code Execution
119
CWE
Product Name: McAfee Virtual Technician
Affected Version From: McAfee Virtual Technician 6.3.0.1911
Affected Version To: McAfee Virtual Technician (latest version)
Patch Exists: YES
Related CWE:
CPE: a:mcafee:virtual_technician:6.3.0.1911
Platforms Tested: Microsoft Windows Vista sp2, Microsoft Windows 2003 r2 sp2, Internet Explorer 7/8/9
McAfee Virtual Technician 6.3.0.1911 MVT.MVTControl.6300 ActiveX Control GetObject() Security Bypass Remote Code Execution Vulnerability
The McAfee Virtual Technician 6.3.0.1911 ActiveX Control has a vulnerability that allows an attacker to bypass security and execute remote code. This vulnerability is due to the unsafe implementation of the GetObject() function in the control. By specifying the ProgID of an arbitrary class from the underlying operating system, an attacker can load and execute operating system commands. Additionally, it is possible to crash the browser by specifying an arbitrary memory address.
Mitigation:
The vendor has released a patch to address this vulnerability. Users are advised to update to the latest version of the McAfee Virtual Technician.