vendor:
Security Scan Plus
by:
Silent Signal
9,8
CVSS
CRITICAL
Remote Code Execution
78
CWE
Product Name: Security Scan Plus
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: Yes
Related CWE: CVE-2017-3897
CPE: a:mcafee:security_scan_plus
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Remote Code Execution in McAfee Security Scan Plus
McAfee Security Scan Plus retrieves promotional and UI design information from different mcafee.com domains and displays them to the user, typically in the main application window. The vulnerability is caused by multiple factors: Information is retrieved over plaintext HTTP that can be trivially modified by an active network attacker. McAfee Security Scan Plus rely on the MCBRWSR2.DLL library to display HTML content. The Library exposes the LaunchApplication() JavaScript API that executes arbitrary commands on the affected system.
Mitigation:
The vendor has released patches to address this vulnerability.