Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 =========================================================================== AUSCERT Security Bulletin ASB-2013.0049 A vulnerability has been identified in McAfee Virtual Technician (MVT) 3 April 2013 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: McAfee Virtual Technician Operating System: UNIX variants (UNIX, Linux, OSX) Windows Impact/Access: Increased Privileges -- Remote with User Interaction Resolution: Patch/Upgrade CVE Names: CVE-2012-5879 Member content until: Friday, May 3 2013 OVERVIEW A vulnerability has been identified in McAfee Virtual Technician (MVT) prior to version 7.1. [1] IMPACT The vendor has provided the following details regarding this vulnerability: "MVT 6.5 and earlier contain a vulnerability where the Save() function could be used to cause an escalation of privileges. This issue mainly affects Consumer users, but can also affects Enterprise users who use MVT or have deployed ePO-MVT to systems in their environments for diagnostic purposes. MVT is not tied to a particular McAfee product. Any system could have MVT installed; potentially even systems that do not have McAfee products currently installed." [1] MITIGATION The vendor recommends updating to the latest version of MVT to correct this issue. [1] REFERENCES [1] McAfee Security Bulletin - McAfee MVT & ePO-MVT update fixes an "Escalation of Privileges" vulnerability https://kc.mcafee.com/corporate/index?page=content&id=SB10040 AusCERT has made every effort to ensure that the information contained in this document is accurate. However, the decision to use the information described is the responsibility of each user or organisation. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBUVu11u4yVqjM2NGpAQLY+RAAo2pJ4aKHI3D2H82ZMEo8lAIF4alnb4n0 W5hDWMgB78ytMOvF3+ViIMbAb0CxIKPSyYn8yAViSYn+qcpcCTBnVtBq571fLyfO bqDHTcRzR7Bamc85z7zchxMTxuraaTR/imT7Zw2J9ETHzQicwvbjLsZIpKl4T7B/ xLAsKcpmbRRxNxJeaapbZeDsyKR3TDc6jXtM0UjSEZm3xPuBjquwqq3uIPPOBXzO KlMMGioswdRXgHx3aO7S69CHBYGnyt8D/CFNYEF3x6e8eE2ZPfwm/6QSgX7isJWF ZRqyQS92JlD6pYP4uUWWppCyiQtpsEboXXSXUuUiG6zBZ+I/Pt2Dfois9CnMdZNa wYDPV33ZSnpssVvgardp5ZPi9eoY0/dzXk2ckRiSpvGyDoJkMoJW61/4AlUA6WzZ 0jEmM8iQ0fu6snGv4eT9khfWVWnvm33Kd8UWkspAoSI/va80JXehza77BS2IM2Vc 0mtCsL9O2bDCAAhLiJkvEblHJWTLrF//jcaetYn/+8dp+eB1toqWo/fRt/7kB1Qe s7gjnSycFWoPh5TGsT7U1MSbjhbTU8dpc/4kJ3RwYB6d7j0HmggRXhBG00KclMkq ppECoDHDEuHXsgxC4uijFw7Q6M9++1dUciqiYM7hFGS5RtlZRY+5FIVm1P4UlLcg /faQjZYiQgY= =/JVx -----END PGP SIGNATURE-----