First published: Tue Sep 19 2006(Updated: )
The VirusScan On-Access Scan component in McAfee VirusScan Enterprise 7.1.0 and Scan Engine 4.4.00 allows local privileged users to bypass security restrictions and disable the On-Access Scan option by opening the program via the task bar and quickly clicking the Disable button, possibly due to an interface-related race condition.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Anti-Malware Scan Engine | =4.4.00 | |
McAfee VirusScan Enterprise | =7.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-4886 has been classified as a high severity vulnerability due to its potential for local privilege escalation.
CVE-2006-4886 allows local privileged users to disable the On-Access Scan by quickly interacting with the application interface.
CVE-2006-4886 affects McAfee VirusScan Enterprise version 7.1.0 and Scan Engine version 4.4.00.
CVE-2006-4886 can significantly weaken system security by allowing the disabling of real-time scanning.
Organizations can mitigate CVE-2006-4886 by applying patches and updates provided by McAfee for the affected software.