7.2

CVE-2005-4505

Exploit
Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Common Management Agent Version 3.5 Update p5
Mcafee ≫ Virusscan Enterprise Version 8.0i Update p11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.578
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://reedarvin.thearvins.com/20051222-01.html
http://securityreason.com/securityalert/292
http://securitytracker.com/id?1015404
http://www.securityfocus.com/archive/1/420104/100/0/threaded
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/16040
Exploit
http://www.vupen.com/english/advisories/2005/3077
https://exchange.xforce.ibmcloud.com/vulnerabilities/23815