McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
BID:16040
Info
McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
| Bugtraq ID: | 16040 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 22 2005 12:00AM |
| Updated: | Dec 22 2005 12:00AM |
| Credit: | Discovered by Reed Arvin <[email protected]>. |
| Vulnerable: |
McAfee VirusScan Enterprise 8.0 i patch 11 |
| Not Vulnerable: | |
Discussion
McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
McAfee VirusScan is prone to a vulnerability that could allow an arbitrary file to be executed.
The 'naPrdMgr.exe' process calls applications without using properly quoted paths. Successful exploitation may allow local attackers to gain elevated privileges.
McAfee VirusScan Enterprise 8.0i (patch 11) is reportedly vulnerable. Other versions may be affected as well.
McAfee VirusScan is prone to a vulnerability that could allow an arbitrary file to be executed.
The 'naPrdMgr.exe' process calls applications without using properly quoted paths. Successful exploitation may allow local attackers to gain elevated privileges.
McAfee VirusScan Enterprise 8.0i (patch 11) is reportedly vulnerable. Other versions may be affected as well.
Exploit / POC
McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
An exploit is not required.
The following proof of concept by Reed Arvin is available:
An exploit is not required.
The following proof of concept by Reed Arvin is available:
Solution / Fix
McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
Solution:
It has been reported that McAfee VirusScan Enterprise 8.0i patch 12 is not vulnerable to this issue. This could not be confirmed by Symantec. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
It has been reported that McAfee VirusScan Enterprise 8.0i patch 12 is not vulnerable to this issue. This could not be confirmed by Symantec. Please contact the vendor for more information.
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
McAfee VirusScan Path Specification Local Privilege Escalation Vulnerability
References:
References: