Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
McAfee VirusScan MCINSCTL.DLL ActiveX控件任意文件覆盖漏洞
Vulnerability Description
McAfee VirusScan是一款流行的杀毒软件。 McAfee在处理ActiveX控件存在漏洞,攻击者可能利用此漏洞在服务器上执行任意指令。 注册的ActiveX控件无法限制哪些域可以加载执行该控件,导致McAfee VirusScan中存在访问控制漏洞。具体来说,McAfee Security Center捆绑的MCINSCTL.DLL导出一个被称为MCINSTALL.McLog的对象用于记录。McLog对象允许Security Center通过StartLog和AddLog方式记录文件。McAf
CVSS Information
N/A
Vulnerability Type
N/A