McAfee VirusScan WebScanX Code Execution Vulnerability
BID:6288
Info
McAfee VirusScan WebScanX Code Execution Vulnerability
| Bugtraq ID: | 6288 |
| Class: | Origin Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 02 2002 12:00AM |
| Updated: | Dec 02 2002 12:00AM |
| Credit: | Discovery is credited to Jari Helenius <[email protected]>. |
| Vulnerable: |
McAfee VirusScan 4.5.1 |
| Not Vulnerable: | |
Discussion
McAfee VirusScan WebScanX Code Execution Vulnerability
McAfee VirusScan's WebScanX component hooks into explorer.exe on Microsoft Windows systems. When explorer is used to browse directories (local or network), and the user's home directory is located on a network share, WebScanX calls several .dll files from the user's home directory.
If one of these called .dll files contained attacker-supplied code, it would be executed by WebScanX in the local System context.
McAfee VirusScan's WebScanX component hooks into explorer.exe on Microsoft Windows systems. When explorer is used to browse directories (local or network), and the user's home directory is located on a network share, WebScanX calls several .dll files from the user's home directory.
If one of these called .dll files contained attacker-supplied code, it would be executed by WebScanX in the local System context.
Solution / Fix
McAfee VirusScan WebScanX Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.