The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2005-12-21T11:00:00

Updated: 2024-08-07T23:17:23.394Z

Reserved: 2005-11-18T00:00:00

Link: CVE-2005-3657

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2005-12-21T11:03:00.000

Modified: 2011-03-08T02:26:56.377

Link: CVE-2005-3657

cve-icon Redhat

No data.