CVE Vulnerabilities

CVE-2007-1538

Published: Mar 20, 2007 | Modified: May 17, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

McAfee VirusScan Enterprise 8.5.0.i uses insecure permissions for certain Windows Registry keys, which allows local users to bypass local password protection via the UIP value in (1) HKEY_LOCAL_MACHINESOFTWAREMcAfeeDesktopProtection or (2) HKEY_LOCAL_MACHINESOFTWARENetwork AssociatesTVDVirusScan EntrepriseCurrentVersion. NOTE: this issue has been disputed by third-party researchers, stating that the default permissions for HKEY_LOCAL_MACHINESOFTWARE does not allow for write access and the product does not modify the inherited permissions. There might be an interaction error with another product

Affected Software

Name Vendor Start Version End Version
Virusscan_enterprise Mcafee 8.5i (including) 8.5i (including)

References