First published: Wed Aug 22 2012(Updated: )
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to execute arbitrary code or cause a denial of service (Internet Explorer crash) via a crafted web site.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Virtual Technician | <=6.3.0.1911 | |
McAfee Virtual Technician | <=1.0.7 | |
McAfee Virtual Technician | =1.0 | |
McAfee Virtual Technician | =1.0.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4598 has a high severity rating due to its potential for remote code execution.
To mitigate CVE-2012-4598, upgrade to McAfee Virtual Technician version 6.4 or later.
CVE-2012-4598 allows attackers to execute arbitrary code or cause a denial of service through crafted web pages.
CVE-2012-4598 affects McAfee Virtual Technician versions prior to 6.4 and various versions of ePO-MVT.
Yes, CVE-2012-4598 can lead to Internet Explorer crashing as part of the denial of service attack.