{"api_version":"1","generated_at":"2026-07-23T20:15:11+00:00","cve":"CVE-2013-7460","urls":{"html":"https://cve.report/CVE-2013-7460","api":"https://cve.report/api/cve/CVE-2013-7460.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-7460","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-7460"},"summary":{"title":"CVE-2013-7460","description":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.","state":"PUBLISHED","assigner":"intel","published_at":"2017-03-14 22:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-284","A write protection and execution bypass vulnerability"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"McAfee KnowledgeBase - McAfee Security Bulletin – Application Control / Change Control for Linux update fixes a write protection and execution bypass vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-7460","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7460","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Intel","product":"Application Control (MAC)","version":"affected 6.1.0 for Linux and earlier","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"7460","vulnerable":"1","versionEndIncluding":"6.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"application_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"7460","vulnerable":"1","versionEndIncluding":"6.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"change_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:09:16.990Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Application Control (MAC)","vendor":"Intel","versions":[{"status":"affected","version":"6.1.0 for Linux and earlier"}]}],"datePublic":"2013-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions."}],"problemTypes":[{"descriptions":[{"description":"A write protection and execution bypass vulnerability","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-03-14T21:57:01.000Z","orgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","shortName":"intel"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@intel.com","ID":"CVE-2013-7460","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Application Control (MAC)","version":{"version_data":[{"version_value":"6.1.0 for Linux and earlier"}]}}]},"vendor_name":"Intel"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"A write protection and execution bypass vulnerability"}]}]},"references":{"reference_data":[{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}]}}}},"cveMetadata":{"assignerOrgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","assignerShortName":"intel","cveId":"CVE-2013-7460","datePublished":"2017-03-14T22:00:00.000Z","dateReserved":"2017-02-27T00:00:00.000Z","dateUpdated":"2024-08-06T18:09:16.990Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-14 22:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-284","A write protection and execution bypass vulnerability"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:application_control:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.1.0","matchCriteriaId":"70954478-492A-4133-B9C2-763E58B39C2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:change_control:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.1.0","matchCriteriaId":"1FA809D9-F44D-46C8-9663-02E75574CC51"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"7460","Ordinal":"1","Title":"CVE-2013-7460","CVE":"CVE-2013-7460","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"7460","Ordinal":"1","NoteData":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.","Type":"Description","Title":"CVE-2013-7460"},{"CveYear":"2013","CveId":"7460","Ordinal":"2","NoteData":"2017-03-14","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"7460","Ordinal":"3","NoteData":"2017-03-14","Type":"Other","Title":"Modified"}]}}}