CVE-2011-3007
The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by…
Does this matter?
Lower severity and a low EPSS score (1.19%). Track it; it rarely justifies an emergency change on its own.
Description
The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.19% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- mcafee/saas endpoint protection
- Source
- cve@mitre.org
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-11-13
- http://osvdb.org/74513
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69093
- https://kc.mcafee.com/corporate/index?page=content&id=SB10016Vendor Advisory
- http://dvlabs.tippingpoint.com/advisory/TPTI-11-13
- http://osvdb.org/74513
- https://exchange.xforce.ibmcloud.com/vulnerabilities/69093
- https://kc.mcafee.com/corporate/index?page=content&id=SB10016Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.