McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
BID:49088
Info
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
| Bugtraq ID: | 49088 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2011 12:00AM |
| Updated: | Aug 08 2011 12:00AM |
| Credit: | Jonathan Andersson |
| Vulnerable: |
McAfee SaaS Endpoint Protection 5.2.1 |
| Not Vulnerable: |
McAfee SaaS Endpoint Protection 5.2.2 |
Discussion
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
McAfee SaaS Endpoint Protection is prone to a remote code-execution vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of the application running the ActiveX control (typically Internet Explorer).
McAfee SaaS Endpoint Protection 5.2.1 and prior are vulnerable.
McAfee SaaS Endpoint Protection is prone to a remote code-execution vulnerability.
Exploiting this issue allows remote attackers to execute arbitrary code in the context of the application running the ActiveX control (typically Internet Explorer).
McAfee SaaS Endpoint Protection 5.2.1 and prior are vulnerable.
Exploit / POC
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
Currently we are not aware of any exploits for the issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits for the issue. If you feel we are in error or if you are aware of any more recent information, please mail us at: [email protected].
Solution / Fix
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
Solution:
Updates are available to address this issue. Please see the references for more information.
Solution:
Updates are available to address this issue. Please see the references for more information.
References
McAfee SaaS Endpoint Protection 'MyAsUtil5.2.0.603.dll' ActiveX Remote Code Execution Vulnerability
References:
References:
- McAfee Homepage (McAfee)
- McAfee SaaS MyAsUtil5.2.0.603.dll SecureObjectFactory Instantiation Design Flaw (Jonathan Andersson)
- McAfee Security Bulletin - McAfee SaaS Endpoint Protection update fixes multiple (Jonathan Andersson)