// For flags

CVE-2018-6690

McAfee Application Control (MAC) - Whitelist bypass using a hard drive solidified by MACC

Severity Score

7.1
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

Una vulnerabilidad de acceso, modificación o ejecución de archivos ejecutables en el cliente Microsoft Windows en McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 y anteriores permite que usuarios autenticados ejecuten código arbitrario mediante la transferencia de archivos del sistema externo.

*Credits: McAfee credits Paul W for reporting this flaw.
CVSS Scores
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
High
Availability
None
Attack Vector
Local
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2018-02-06 CVE Reserved
  • 2018-09-18 CVE Published
  • 2023-03-08 EPSS Updated
  • 2024-08-05 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-346: Origin Validation Error
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
<= 7.0.2
Search vendor "Mcafee" for product "Application Change Control" and version " <= 7.0.2"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
8.0.0
Search vendor "Mcafee" for product "Application Change Control" and version "8.0.0"
-
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
8.0.0
Search vendor "Mcafee" for product "Application Change Control" and version "8.0.0"
hotfix1
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
8.0.0
Search vendor "Mcafee" for product "Application Change Control" and version "8.0.0"
hotfix2
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
8.0.0
Search vendor "Mcafee" for product "Application Change Control" and version "8.0.0"
hotfix3
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe
Mcafee
Search vendor "Mcafee"
Application Change Control
Search vendor "Mcafee" for product "Application Change Control"
8.0.0
Search vendor "Mcafee" for product "Application Change Control" and version "8.0.0"
hotfix4
Affected
in Microsoft
Search vendor "Microsoft"
Windows
Search vendor "Microsoft" for product "Windows"
--
Safe