CVE-2018-6669: Bypass Application Control through an ASP.NET form
Published Dec 20, 2018
·Updated
A whitelist bypass vulnerability in McAfee Application Control / Change Control 7.0.1 and before allows a remote or local user to execute blacklisted files through an ASP.NET form.
Affected Software
1 affected component
McAfee Application Change Control<=7.0.1
Remediation
Information
Install or update to McAfee Application and Change Control (MACC) Application 8.0.0 and MACC ePO extension 8.0.0 or later.
Event History
Dec 20, 2018
CVE Published
01:29 PM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-6669?
CVE-2018-6669 has a severity rating of medium due to the potential for unauthorized execution of blacklisted files.
2
How do I fix CVE-2018-6669?
To fix CVE-2018-6669, upgrade McAfee Application Control / Change Control to version 7.0.2 or later.
3
Who is affected by CVE-2018-6669?
CVE-2018-6669 affects users of McAfee Application Control / Change Control versions 7.0.1 and earlier.
4
What type of vulnerability is CVE-2018-6669?
CVE-2018-6669 is classified as a whitelist bypass vulnerability.
5
Can CVE-2018-6669 be exploited remotely?
Yes, CVE-2018-6669 can be exploited by both remote and local users.