5
CVE-2005-3657
- EPSS 2.32%
- Veröffentlicht 21.12.2005 11:03:00
- Zuletzt bearbeitet 16.06.2026 22:17:21
- Erkennungen
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Mcinsctl.Dll Version 4.0.0.83
Mcafee ≫ Virusscan Security Center Version 4.0
Mcafee ≫ Virusscan Security Center Version 4.0.3
Mcafee ≫ Virusscan Security Center Version 4.5
Mcafee ≫ Virusscan Security Center Version 4.5.1
Mcafee ≫ Virusscan Security Center Version 5.0
Mcafee ≫ Virusscan Security Center Version 6.0
Mcafee ≫ Virusscan Security Center Version 7.0
Mcafee ≫ Virusscan Security Center Version 7.1
Mcafee ≫ Virusscan Security Center Version 8.0
Mcafee ≫ Virusscan Security Center Version 9.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.32% | 0.812 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/18169
http://securityreason.com/securityalert/279
http://securitytracker.com/id?1015390
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=358
http://www.securityfocus.com/bid/15986
http://www.vupen.com/english/advisories/2005/3006