CVE-2012-4598: Critical severity McAfee McAfee Virtual Technician vulnerability
Published Aug 22, 2012
·Updated
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause a denial of service (Internet Explorer crash) via a crafted web site.
Affected Software
4 affected components
McAfee McAfee Virtual Technician<=6.3.0.1911
McAfee Epo Mcafee Virtual Technician<=1.0.7
McAfee Epo Mcafee Virtual Technician=1.0
McAfee Epo Mcafee Virtual Technician=1.0.4.0
Event History
Aug 22, 2012
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-4598?
CVE-2012-4598 has a high severity rating due to its potential for remote code execution.
2
How do I fix CVE-2012-4598?
To mitigate CVE-2012-4598, upgrade to McAfee Virtual Technician version 6.4 or later.
3
What types of attacks are possible with CVE-2012-4598?
CVE-2012-4598 allows attackers to execute arbitrary code or cause a denial of service through crafted web pages.
4
Which versions of McAfee Virtual Technician are affected by CVE-2012-4598?
CVE-2012-4598 affects McAfee Virtual Technician versions prior to 6.4 and various versions of ePO-MVT.
5
Is Internet Explorer affected by CVE-2012-4598?
Yes, CVE-2012-4598 can lead to Internet Explorer crashing as part of the denial of service attack.