CVE-2009-5118: Critical severity mcafee virusscan vulnerability
Published Aug 22, 2012
·Updated
Untrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, as demonstrated by scanning a document located on a remote share.
Affected Software
3 affected components
McAfee VirusScan Enterprise<=8.5i
McAfee VirusScan Enterprise=8.0i
McAfee VirusScan Enterprise=8.0i-p11
Event History
Aug 22, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2009-5118?
CVE-2009-5118 is classified as a local privilege escalation vulnerability.
2
How do I fix CVE-2009-5118?
To mitigate CVE-2009-5118, update McAfee VirusScan Enterprise to version 8.7i or later.
3
What versions of McAfee VirusScan Enterprise are affected by CVE-2009-5118?
CVE-2009-5118 affects McAfee VirusScan Enterprise versions 8.0i and 8.5i.
4
Can CVE-2009-5118 be exploited over a network?
Yes, CVE-2009-5118 can be exploited through a network by scanning documents located on remote shares.
5
Who can exploit CVE-2009-5118?
CVE-2009-5118 can be exploited by local users with access to the affected software.