McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
BID:14549
Info
McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
| Bugtraq ID: | 14549 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-2554 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 11 2005 12:00AM |
| Updated: | Jul 12 2009 05:06PM |
| Credit: | Reed Arvin <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Network Associates McAfee ePolicy Orchestrator 3.5 .0 patch 3 |
| Not Vulnerable: | |
Discussion
McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
Network Associates McAfee ePolicy Orchestrator is susceptible to a local information disclosure vulnerability. This issue is due to incorrectly configured directory permissions in the default installation process of the application.
This vulnerability allows local attackers to access arbitrary files located in the same partition as the affected directory with SYSTEM privileges. This will aid them in further attacks.
Network Associates McAfee ePolicy Orchestrator is susceptible to a local information disclosure vulnerability. This issue is due to incorrectly configured directory permissions in the default installation process of the application.
This vulnerability allows local attackers to access arbitrary files located in the same partition as the affected directory with SYSTEM privileges. This will aid them in further attacks.
Exploit / POC
McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
McAfee reports that they will be releasing CMA 3.5 patch 4 to address this issue no later than August 19, 2005. Please see Solution ID kb42216 in the References section for further details.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
McAfee reports that they will be releasing CMA 3.5 patch 4 to address this issue no later than August 19, 2005. Please see Solution ID kb42216 in the References section for further details.
References
McAfee ePolicy Orchestrator Local Information Disclosure Vulnerability
References:
References:
- Solution ID kb42216 - Security Vulnerability in Common Management Agent 3.X (McAfee)
- ePolicy Orchestrator Homepage (Network Associates Inc.)
- Privilege escalation in Network Associates ePolicy Orchestrator Agent 3.5.0 (pat (Reed Arvin
)