Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious program.exe file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted Program Files path.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Common_management_agent | Mcafee | 3.5-p5 (including) | 3.5-p5 (including) |
Virusscan_enterprise | Mcafee | 8.0i-p11 (including) | 8.0i-p11 (including) |