CVE
- Id
- 2695
- CVE No.
- CVE-2000-1128
- Status
- Candidate
- Description
- The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:Program Files directory.
- Phase
- Proposed (20001219)
- Votes
- ACCEPT(1) Cole | MODIFY(1) Frech | REVIEWING(1) Wall
- Comments
- Frech> XF:nai-virusscan-unquoted-imagepath(5484)