CVE-2011-3007

N/A Unknown
Published: August 10, 2011 Modified: April 29, 2026
View on NVD

Description

The myCIOScn ActiveX control (myCIOScn.dll) in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to write to arbitrary files by specifying an arbitrary filename in the MyCioScan.Scan.ReportFile parameter, as demonstrated by injecting script into a log file and executing arbitrary code using the MyCioScan.Scan.Start method.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://osvdb.org/74513
Source: cve@mitre.org
http://dvlabs.tippingpoint.com/advisory/TPTI-11-13
Source: af854a3a-2127-422b-91ae-364da2661108
http://osvdb.org/74513
Source: af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/69093
Source: af854a3a-2127-422b-91ae-364da2661108
https://kc.mcafee.com/corporate/index?page=content&id=SB10016
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

8 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
1.2%
64th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

mcafee