First published: Fri Mar 02 2007(Updated: )
McAfee VirusScan for Mac (Virex) before 7.7 patch 1 has weak permissions (0666) for /Library/Application Support/Virex/VShieldExclude.txt, which allows local users to reconfigure Virex to skip scanning of arbitrary files.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee VirusScan Plus | <=7.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1226 is classified as a medium severity vulnerability due to its potential to allow local users to alter security configurations.
To fix CVE-2007-1226, update McAfee VirusScan for Mac to version 7.7 patch 1 or higher.
CVE-2007-1226 affects McAfee VirusScan for Mac (Virex) versions prior to 7.7 patch 1.
An attacker can exploit CVE-2007-1226 to modify the Virex configuration and prevent the antivirus from scanning certain files.
Yes, CVE-2007-1226 is considered relatively easy to exploit since it requires local access to the system.