First published: Thu Dec 20 2018(Updated: )
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.
Credit: psirt@mcafee.com
Affected Software | Affected Version | How to fix |
---|---|---|
Mcafee Application Change Control | <=7.0.1 |
Install or update to McAfee Application and Change Control (MACC) Application 8.0.0 and MACC ePO extension 8.0.0 or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6669 has a severity rating of medium due to the potential for unauthorized execution of blacklisted files.
To fix CVE-2018-6669, upgrade McAfee Application Control / Change Control to version 7.0.2 or later.
CVE-2018-6669 affects users of McAfee Application Control / Change Control versions 7.0.1 and earlier.
CVE-2018-6669 is classified as a whitelist bypass vulnerability.
Yes, CVE-2018-6669 can be exploited by both remote and local users.