|
McAfee VirusScan privilege escalation
|
|
Secunia Advisory:
|
SA7637
|
|
|
Release Date:
|
2002-12-03
|
|
Popularity:
|
7,684 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Privilege escalation
|
|
Where:
|
Local system
|
|
Solution Status:
|
Unpatched
|
|
| Software: | McAfee VirusScan 4.x
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
Description: McAfee VirusScan includes WebScanX.exe which searches for DLL files in %HOMEDRIVE%, %HOMEPATH% and %HOMESHARE%.
This allows malicious users to place trojan DLL files in one of the above mentioned locations. WebScanX.exe runs as LocalSystem, thus the user could gain local administrative privileges.
This could also be abused from remote if an attacker made a user download a trojan DLL file or if another vulnerability allowed attackers to place local files from remote.
If Download Scan or Internet Filter is enabled, the program WebScanX.exe is running. WebScanX.exe is also integrated with explorer.exe.
Solution: The only workaround is to disable Download Scan and Internet Filter, this may however not be a desirable action. According to McAfee these option only provides little extra security.
None of the following DLL files should exist outside %systemroot%/system32:
mswsock.dll, regemul.dll, msjava.dll, psapi.dll, setupapi.dll, browseui.dll.
Provided and/or discovered by: Jari Helenius
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
7th Oct, 2008
|
New advisories:
|
19 |
|
New vulnerabilities:
|
68 |
|
Updated advisories:
|
62 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
Solutions | More...
|
|