CVE-2000-1128: Medium severity McAfee VirusScan vulnerability
The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2000-1128?
CVE-2000-1128 has a moderate severity rating due to the potential for local users to exploit the vulnerability.
How do I fix CVE-2000-1128?
To fix CVE-2000-1128, ensure that the ImagePath variable is properly quoted in the configuration settings.
Who is affected by CVE-2000-1128?
CVE-2000-1128 affects users of McAfee VirusScan 4.5 with its default configuration.
What is the impact of CVE-2000-1128?
The impact of CVE-2000-1128 allows local users to execute a Trojan horse program by manipulating the application’s search path.
Is there a workaround for CVE-2000-1128?
A possible workaround for CVE-2000-1128 is to change the default configuration of the application to secure the ImagePath variable.