CNCVE编号:CNCVE-20001128 CVE编号:CAN-2000-1128 安全级别:高 漏洞中文描述: McAfee VirusScan 4.5的默认配置不能正确的引用ImagePath变量,这会导致搜索路径设置不正确并允许本地用户将特洛伊木马“common.exe”程序放置在C:Pragram Files目录下。 漏洞英文描述: The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory. 漏洞参考: NTBUGTRAQ:20001103 Elevation of Privileges Exploit with McAfee VirusScan 4.5 | URL:http://archives.neohapsis.com/archives/ntbugtraq/2000-q4/0073.html | BID:1920 | URL:http://www.securityfocus.com/bid/1920 系统类型: Unix/Linux Win95/98/ME Win2000/NT 漏洞类型:设计错误