PoC Index

CVE-2005-4505

HIGH 7.2EPSS 1.0%

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
0.99% chance of exploitation in the next 30 days, 60th percentile
Published
2005-12-23
Updated
2024-08-07

ExploitDB entries (1)

References

Related