Vulnerabilities > CVE-2005-4505 - Local Privilege Escalation vulnerability in McAfee VirusScan Path Specification

047910
CVSS 7.2 - HIGH
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
low complexity
mcafee
exploit available

Summary

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

Vulnerable Configurations

Part Description Count
Application
Mcafee
2

Exploit-Db

descriptionMcAfee VirusScan 8.0 Path Specification Local Privilege Escalation Vulnerability. CVE-2005-4505. Local exploit for windows platform
idEDB-ID:26970
last seen2016-02-03
modified2005-12-22
published2005-12-22
reporterReed Arvin
sourcehttps://www.exploit-db.com/download/26970/
titleMcAfee VirusScan 8.0 - Path Specification Local Privilege Escalation Vulnerability