{"api_version":"1","generated_at":"2026-07-23T19:55:58+00:00","cve":"CVE-2013-7461","urls":{"html":"https://cve.report/CVE-2013-7461","api":"https://cve.report/api/cve/CVE-2013-7461.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2013-7461","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2013-7461"},"summary":{"title":"CVE-2013-7461","description":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.","state":"PUBLISHED","assigner":"intel","published_at":"2017-03-14 22:59:00","updated_at":"2025-04-20 01:37:25"},"problem_types":["CWE-284","A write protection and execution bypass vulnerability"],"metrics":[{"version":"3.0","source":"nvd@nist.gov","type":"Primary","score":"5.5","severity":"MEDIUM","vector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","data":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"}},{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.1","severity":"","vector":"AV:L/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"McAfee KnowledgeBase - McAfee Security Bulletin – Application Control / Change Control for Linux update fixes a write protection and execution bypass vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2013-7461","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2013-7461","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Intel","product":"Change Control (MCC)","version":"affected 6.1.0 for Linux and earlier","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2013","cve_id":"7461","vulnerable":"1","versionEndIncluding":"6.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"application_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"},{"cve_year":"2013","cve_id":"7461","vulnerable":"1","versionEndIncluding":"6.1.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mcafee","cpe5":"change_control","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"linux","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T18:09:17.246Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"Change Control (MCC)","vendor":"Intel","versions":[{"status":"affected","version":"6.1.0 for Linux and earlier"}]}],"datePublic":"2013-09-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions."}],"problemTypes":[{"descriptions":[{"description":"A write protection and execution bypass vulnerability","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-03-14T21:57:01.000Z","orgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","shortName":"intel"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@intel.com","ID":"CVE-2013-7461","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Change Control (MCC)","version":{"version_data":[{"version_value":"6.1.0 for Linux and earlier"}]}}]},"vendor_name":"Intel"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"A write protection and execution bypass vulnerability"}]}]},"references":{"reference_data":[{"name":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054","refsource":"CONFIRM","url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10054"}]}}}},"cveMetadata":{"assignerOrgId":"6dda929c-bb53-4a77-a76d-48e79601a1ce","assignerShortName":"intel","cveId":"CVE-2013-7461","datePublished":"2017-03-14T22:00:00.000Z","dateReserved":"2017-02-27T00:00:00.000Z","dateUpdated":"2024-08-06T18:09:17.246Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2017-03-14 22:59:00","lastModifiedDate":"2025-04-20 01:37:25","problem_types":["CWE-284","A write protection and execution bypass vulnerability"],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:N/I:P/A:N","baseScore":2.1,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":3.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:application_control:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.1.0","matchCriteriaId":"70954478-492A-4133-B9C2-763E58B39C2A"},{"vulnerable":true,"criteria":"cpe:2.3:a:mcafee:change_control:*:*:*:*:*:linux:*:*","versionEndIncluding":"6.1.0","matchCriteriaId":"1FA809D9-F44D-46C8-9663-02E75574CC51"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2013","CveId":"7461","Ordinal":"1","Title":"CVE-2013-7461","CVE":"CVE-2013-7461","Year":"2013"},"notes":[{"CveYear":"2013","CveId":"7461","Ordinal":"1","NoteData":"A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.","Type":"Description","Title":"CVE-2013-7461"},{"CveYear":"2013","CveId":"7461","Ordinal":"2","NoteData":"2017-03-14","Type":"Other","Title":"Published"},{"CveYear":"2013","CveId":"7461","Ordinal":"3","NoteData":"2017-03-14","Type":"Other","Title":"Modified"}]}}}