TITLE:
McAfee Internet Security Suite 2005 Insecure File Permissions

SECUNIA ADVISORY ID:
SA14989

VERIFY ADVISORY:
http://secunia.com/advisories/14989/

CRITICAL:
Less critical

IMPACT:
Manipulation of data, Privilege escalation

WHERE:
Local system

SOFTWARE:
McAfee Internet Security Suite 2005
http://secunia.com/product/4930/

DESCRIPTION:
A security issue has been reported in McAfee Internet Security 
Suite
2005, which can be exploited by malicious, local users to gain
escalated privileges.

The problem is caused due to insecure default file ACLs 
allowing
non-administrative users to modify the installed files. This 
can be
exploited to gain escalated privileges by e.g. replacing a 
program
running as a system service with a malicious program.

SOLUTION:
The vendor has reportedly acknowledged the security issue and 
is
providing automated fixes.

ORIGINAL ADVISORY:
iDEFENSE:
http://www.idefense.com/application/poi/display?id=233&type=vulnerabilities
============= PCWorks Mailing List =================
Don't see your post? Check our posting guidelines &
make sure you've followed proper posting procedures,
http://pcworkers.com/rules.htm
Contact list owner <[EMAIL PROTECTED]>
Unsubscribing and other changes: http://pcworkers.com
=====================================================

Reply via email to