CVE-2014-9920
Summary
| CVE | CVE-2014-9920 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-14 22:59:00 UTC |
| Updated | 2017-03-29 13:41:00 UTC |
| Description | Unauthorized execution of binary vulnerability in McAfee (now Intel Security) McAfee Application Control (MAC) 6.0.0 before hotfix 9726, 6.0.1 before hotfix 9068, 6.1.0 before hotfix 692, 6.1.1 before hotfix 399, 6.1.2 before hotfix 426, and 6.1.3 before hotfix 357 and earlier allows attackers to create a malformed Windows binary that is considered non-executable and is not protected through the whitelisting protection feature via a specific set of circumstances. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Mcafee | Application Control | 6.0.0 | All | All | All |
| Application | Mcafee | Application Control | 6.0.1 | All | All | All |
| Application | Mcafee | Application Control | 6.1.0 | All | All | All |
| Application | Mcafee | Application Control | 6.1.1 | All | All | All |
| Application | Mcafee | Application Control | 6.1.2 | All | All | All |
| Application | Mcafee | Application Control | 6.1.3 | All | All | All |
| Application | Mcafee | Application Control | 6.0.0 | All | All | All |
| Application | Mcafee | Application Control | 6.0.1 | All | All | All |
| Application | Mcafee | Application Control | 6.1.0 | All | All | All |
| Application | Mcafee | Application Control | 6.1.1 | All | All | All |
| Application | Mcafee | Application Control | 6.1.2 | All | All | All |
| Application | Mcafee | Application Control | 6.1.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| McAfee KnowledgeBase - McAfee Security Bulletin - McAfee Application Control updates resolve unauthorized execution of binary vulnerability | CONFIRM | kc.mcafee.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.