An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or create arbitrary files via a full pathname argument to the Save method.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
https://kc.mcafee.com/corporate/index?page=content&id=SB10040 | |
http://www.securitytracker.com/id/1028357 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2013-03/0143.html | mailing list exploit |
http://osvdb.org/91700 | vdb entry |
http://www.securityfocus.com/bid/58750 | vdb entry exploit |
https://www.htbridge.com/advisory/HTB23128 |