Release date:
Updated on:
Affected Systems:
McAfee Security-as-a-Service
Description:
--------------------------------------------------------------------------------
Bugtraq id: 51397
McAfee Security-as-a-Service is a comprehensive cloud protection solution.
The ActiveX Control of McAfee SaaS has a security vulnerability, MyCioScan. scan. showReport () directly executes the command passed to the function without verification. Remote attackers can exploit this vulnerability to execute arbitrary code.
<* Source: Andrea Micalizzi A.K. A rgod
Link: http://www.zerodayinitiative.com/advisories/ZDI-12-012/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
McAfee
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.mcafee.com/