Vulnerability Description
McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mcafee | Virusscan | 4.5 |
References
- http://marc.info/?l=bugtraq&m=109526269429728&w=2
- http://www.idefense.com/application/poi/display?id=140&type=vulnerabilitiesPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17367
- http://marc.info/?l=bugtraq&m=109526269429728&w=2
- http://www.idefense.com/application/poi/display?id=140&type=vulnerabilitiesPatchVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17367
FAQ
What is CVE-2004-0831?
CVE-2004-0831 is a vulnerability with a CVSS score of 7.2 (HIGH). McAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray applet, which could allow local users to gain privi...
How severe is CVE-2004-0831?
CVE-2004-0831 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2004-0831?
Check the references section above for vendor advisories and patch information. Affected products include: Mcafee Virusscan.