// For flags

CVE-2012-5879

McAfee Virtual Technician (MVT) 6.5.0.2101 - Insecure ActiveX Method

Severity Score

8.2
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An ActiveX control in McHealthCheck.dll in McAfee Virtual Technician (MVT) and ePO-MVT 6.5.0.2101 and earlier allows remote attackers to modify or create arbitrary files via a full pathname argument to the Save method.

Un control ActiveX en McHealthCheck.dll en McAfee Virtual Technician (MVT) y ePO-MVT-6.5.0.2101 y anteriores permite a atacantes remotos modificar o crear archivos arbitrarios a través de un argumento de ruta completa al método Save.

McAfee Virtual Technician (MVT) 6.5.0.2101 suffers from an exposed unsafe active-x method.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Medium
Authentication
Single
Confidentiality
Complete
Integrity
Complete
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2012-11-16 CVE Reserved
  • 2013-03-27 CVE Published
  • 2013-03-29 First Exploit
  • 2024-09-17 CVE Updated
  • 2024-10-26 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-264: Permissions, Privileges, and Access Controls
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mcafee
Search vendor "Mcafee"
Mcafee Virtual Technician
Search vendor "Mcafee" for product "Mcafee Virtual Technician"
<= 6.5.0.2101
Search vendor "Mcafee" for product "Mcafee Virtual Technician" and version " <= 6.5.0.2101"
-
Affected
Mcafee
Search vendor "Mcafee"
Mcafee Virtual Technician
Search vendor "Mcafee" for product "Mcafee Virtual Technician"
6.3.0.1911
Search vendor "Mcafee" for product "Mcafee Virtual Technician" and version "6.3.0.1911"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
<= 6.5.0.2101
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version " <= 6.5.0.2101"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
1.0
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version "1.0"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
1.0.4.0
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version "1.0.4.0"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
1.0.7
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version "1.0.7"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
1.0.8
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version "1.0.8"
-
Affected
Mcafee
Search vendor "Mcafee"
Epo Mcafee Virtual Technician
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician"
1.0.9
Search vendor "Mcafee" for product "Epo Mcafee Virtual Technician" and version "1.0.9"
-
Affected