CERT-In Vulnerability Note
CIVN-2005-0118
McAfee Security Center MCINSCTL.DLL ActiveX Control File Overwrite Vulnerability
Original Issue Date:December 26, 2005
Severity Rating: HIGH
Systems Affected
McAfee SecurityCenter 6.x McAfee VirusScan 4.x McAfee VirusScan 8.x/2004 McAfee VirusScan 9.x/2005 McAfee VirusScan Professional 7.x McAfee VirusScan Professional 8.x
Overview
A vulnerability exist in McAfee Security Center MCINSCTL.DLL ActiveX , which could be exploited by remote attackers to execute arbitrary commands.
Description
This vulnerability is caused due to an access validation error within the McLog object which does not restrict the domain in which the "mcinsctl.dll" ActiveX control can be instantiated. MCINSCTL.DLL ActiveX control exports an object for logging called MCINSTALL.McLog. An attacker could exploit this vulnerability by creating malicious files in startup folder via hosting a malicious web site and tricking the user to visit the malicious website.
An attacker who successfully exploits this vulnerability could create or append to arbitrary files
Solution
The vulnerability has reportedly been fixed via automatic update
http://www.mcafee.com/myapps/
Vendor Information
Mcafee
http://www.mcafee.com/myapps/
References
iDEFENSE ADVISORY: 12.20.05
http://www.idefense.com/intelligence/vulnerabilities/display.php?id=358
Security Focus
http://www.securityfocus.com/bid/15986
Secunia
http://secunia.com/advisories/18169
FrSIRT
http://www.frsirt.com/english/advisories/2005/3006
CVE Name
CAN-2005-3657
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|