First published: Tue Sep 14 2004(Updated: )
McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee VirusScan | =4.5 | |
McAfee VirusScan | =4.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0831 is considered a medium-severity vulnerability due to the potential for local privilege escalation.
To fix CVE-2004-0831, update McAfee VirusScan to a version that addresses this vulnerability, such as a later release than 4.5.1.
CVE-2004-0831 affects McAfee VirusScan versions 4.5 and 4.5.1.
CVE-2004-0831 can be exploited by local users who have access to the System Scan properties.
The potential impacts of CVE-2004-0831 include unauthorized privilege escalation allowing local users to execute actions with higher system permissions.