CVE-2011-3006
The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS)…
Does this matter?
Lower severity and a low EPSS score (2.13%). Track it; it rarely justifies an emergency change on its own.
Description
The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function, and possibly conduct other unspecified attacks.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 2.13% probability · 81th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- mcafee/saas endpoint protection
- Source
- cve@mitre.org
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-11-12
- http://osvdb.org/74512
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69094
- https://kc.mcafee.com/corporate/index?page=content&id=SB10016Vendor Advisory
- http://dvlabs.tippingpoint.com/advisory/TPTI-11-12
- http://osvdb.org/74512
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69094
- https://kc.mcafee.com/corporate/index?page=content&id=SB10016Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.