- Description
- A write protection and execution bypass vulnerability in McAfee (now Intel Security) Change Control (MCC) 6.1.0 for Linux and earlier allows authenticated users to change files that are part of write protection rules via specific conditions.
- Source
- secure@intel.com
- NVD status
- Analyzed
CVSS 3.0
- Type
- Primary
- Base score
- 5.5
- Impact score
- 3.6
- Exploitability score
- 1.8
- Vector string
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- Severity
- MEDIUM
CVSS 2.0
- Type
- Primary
- Base score
- 2.1
- Impact score
- 2.9
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:N/I:P/A:N
- nvd@nist.gov
- CWE-284
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mcafee:application_control:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "70954478-492A-4133-B9C2-763E58B39C2A",
"versionEndIncluding": "6.1.0"
},
{
"criteria": "cpe:2.3:a:mcafee:change_control:*:*:*:*:*:linux:*:*",
"vulnerable": true,
"matchCriteriaId": "1FA809D9-F44D-46C8-9663-02E75574CC51",
"versionEndIncluding": "6.1.0"
}
],
"operator": "OR"
}
]
}
]