CVE-2005-3657
Summary
| CVE | CVE-2005-3657 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2005-12-21 11:03:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:N/I:P/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Mcinsctl.dll | 4.0.0.83 | All | All | All |
| Application | Mcafee | Virusscan Security Center | All | All | All | All |
| Application | Mcafee | Virusscan Security Center | 4.0 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 4.0.3 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 4.5 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 4.5.1 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 5.0 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 6.0 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 7.0 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 7.1 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 8.0 | All | All | All |
| Application | Mcafee | Virusscan Security Center | 9.0 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee VirusScan Security Center ActiveX Control Arbitrary File Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Accenture | Let there be change | af854a3a-2127-422b-91ae-364da2661108 | www.idefense.com | Vendor Advisory |
| CXSecurity - IDS | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Secunia - Advisories - McAfee SecurityCenter "mcinsctl.dll" ActiveX File Overwrite Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| McAfee SecurityCenter 'MCINSCTL.DLL' Lets Remote Users Create or Overwrite Arbitrary Files on the Target System - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.