McAfee VirusScan Enterprise Local Privilege Escalation (SB10034)

high Nessus Plugin ID 65580

Synopsis

The remote host has an antivirus application installed that is affected by a privilege escalation vulnerability.

Description

The version of McAfee VirusScan Enterprise installed on the remote host is potentially affected by an unspecified local privilege escalation vulnerability. By exploiting this flaw, a local attacker could gain elevated privileges.

Solution

Upgrade to McAfee VirusScan Enterprise 8.7 Patch 5 HF792686 or 8.8 Patch 2 HF805660.

See Also

https://kc.mcafee.com/corporate/index?page=content&id=SB10034

Plugin Details

Severity: High

ID: 65580

File Name: mcafee_vse_privilege_escalation.nasl

Version: 1.9

Type: local

Agent: windows

Family: Windows

Published: 3/15/2013

Updated: 8/7/2018

Supported Sensors: Nessus Agent, Nessus

Risk Information

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/a:mcafee:virusscan, cpe:/a:mcafee:host_intrusion_prevention

Required KB Items: Antivirus/McAfee/installed

Exploit Ease: No known exploits are available

Patch Publication Date: 2/11/2013

Vulnerability Publication Date: 2/11/2013

Reference Information

BID: 57904

MCAFEE-SB: SB10034