CVE-2007-2152

Current Description

Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.

Evaluator Description

The vendor has addressed this issue with the following product update:https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&command=show&forward=nonthreadedKC

Basic Data

PublishedApril 19, 2007
Last ModifiedJuly 29, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:A/AC:M/Au:N/C:C/I:C/A:C
CVSS 2 - Access VectorADJACENT_NETWORK
CVSS 2 - Access ComplexityMEDIUM
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score7.9
SeverityHIGH
Exploitability Score5.5
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationMcafeeVirusscan Enterprise*p11******8.0i

Vulnerable Software List

VendorProductVersions
Mcafee Virusscan Enterprise *

References

NameSourceURLTags
20070417 McAfee VirusScan On-Access Scanner Long Unicode File Name Buffer Overflowhttp://labs.idefense.com/intelligence/vulnerabilities/display.php?id=515IDEFENSEPATCH Vendor Advisory
24914http://secunia.com/advisories/24914SECUNIAPATCH Vendor Advisory
VU#324929http://www.kb.cert.org/vuls/id/324929CERT-VNUS Government Resource
23543http://www.securityfocus.com/bid/23543BID
1017928http://www.securitytracker.com/id?1017928SECTRACKPATCH
ADV-2007-1435http://www.vupen.com/english/advisories/2007/1435VUPEN
mcafee-onaccess-bo(33732)https://exchange.xforce.ibmcloud.com/vulnerabilities/33732XF
https://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&command=show&forward=nonthreadedKChttps://knowledge.mcafee.com/SupportSite/dynamickc.do?externalId=612750&command=show&forward=nonthreCONFIRMPATCH Vendor Advisory