- Description
- A write protection and execution bypass vulnerability in McAfee (now Intel Security) Application Control (MAC) 6.1.0 for Linux and earlier allows authenticated users to change binaries that are part of the Application Control whitelist and allows execution of binaries via specific conditions.
- Source
- secure@intel.com
- NVD status
- Analyzed
CVSS 3.0
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-284
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:application_control:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "70954478-492A-4133-B9C2-763E58B39C2A",
"versionEndIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:mcafee:change_control:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "1FA809D9-F44D-46C8-9663-02E75574CC51",
"versionEndIncluding": "6.1.0"
}
],
"operator": "OR"
}
]
}
]