McAfee Virtual Technician McHealthCheck.dll ActiveX Control Save() Method Arbitrary File Overwrite (SB10040)

high Nessus Plugin ID 65942

Synopsis

An ActiveX control installed on the remote Windows host can be abused to overwrite arbitrary files.

Description

The remote Windows host has a version of the McAfee Virtual Technician / ePolicy Orchestrator McHealthCheck.dll ActiveX control that allows arbitrary files to be corrupted / overwritten due to a flaw in the Save() method.

If an attacker can trick a user on the affected host into viewing a specially crafted HTML document, this issue could potentially be leveraged to overwrite files, potentially leading to remote code execution.

Solution

Upgrade to McAfee Virtual Technician 7.1 / ePolicy Orchestrator 1.1.0 or later.

See Also

https://kc.mcafee.com/corporate/index?page=content&id=SB10040

Plugin Details

Severity: High

ID: 65942

File Name: mcafee_virtual_technician_activex1.nasl

Version: 1.5

Type: local

Agent: windows

Family: Windows

Published: 4/12/2013

Updated: 11/27/2019

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: High

Base Score: 8.2

Temporal Score: 6.4

Vector: CVSS2#AV:N/AC:M/Au:S/C:C/I:C/A:P

CVSS Score Source: CVE-2012-5879

Vulnerability Information

CPE: cpe:/a:mcafee:mcafee_virtual_technician

Required KB Items: SMB/Registry/Enumerated

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 3/26/2013

Vulnerability Publication Date: 3/26/2013

Reference Information

CVE: CVE-2012-5879

BID: 58750

MCAFEE-SB: SB10040