First published: Tue Dec 31 2002(Updated: )
McAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the local hard drive, which allows local users to run arbitrary code via malicious versions of those DLLs.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee VirusScan | =4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-2282 is categorized as a high severity vulnerability due to its potential for arbitrary code execution by local users.
To fix CVE-2002-2282, it is recommended to upgrade to a newer version of McAfee VirusScan that does not contain this vulnerability.
Users of McAfee VirusScan version 4.5.1 are primarily affected by CVE-2002-2282.
CVE-2002-2282 can be exploited through the execution of malicious DLL files placed in the user's home directory.
CVE-2002-2282 was disclosed in December 2002.