CVE-2009-5115: Medium severity mcafee common management agent vulnerability
Published Aug 22, 2012
·Updated
McAfee Common Management Agent (CMA) 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608, and McAfee Agent 4.0 before Patch 3, allows remote authenticated users to overwrite arbitrary files by accessing a report-writing ActiveX control COM object.
Affected Software
12 affected components
McAfee Common Management Agent=3.5.5.438
McAfee Common Management Agent=3.5.5.568
McAfee Common Management Agent=3.5.5.577
McAfee Common Management Agent=3.5.5.580
McAfee Common Management Agent=3.5.5.588
McAfee Common Management Agent=3.6.0.438
McAfee Common Management Agent=3.6.0.453
McAfee Common Management Agent=3.6.0.546
McAfee Common Management Agent=3.6.0.569
McAfee Common Management Agent=3.6.0.574
McAfee Common Management Agent=3.6.0.595
McAfee Common Management Agent=3.6.0.603
Event History
Aug 22, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5115?
CVE-2009-5115 has critical severity due to its potential for remote file overwriting.
2
How do I fix CVE-2009-5115?
To fix CVE-2009-5115, update McAfee Common Management Agent to version 3.6.0.609 or later.
3
What software is affected by CVE-2009-5115?
CVE-2009-5115 affects McAfee Common Management Agent versions 3.5.5 through 3.5.5.588 and 3.6.0 through 3.6.0.608.
4
Who can exploit CVE-2009-5115?
CVE-2009-5115 can be exploited by remote authenticated users with access to the vulnerable software.
5
What are the consequences of CVE-2009-5115?
Exploitation of CVE-2009-5115 allows attackers to overwrite arbitrary files on the affected system.