Vulnerability Solutions

The Nimsoft Cloud Monitor Periodic Vulnerability Scan checks for the vulnerability below. To see the most recently added vulnerability solutions that are scanned by WatchMouse, go to the Vulnerability Solutions overview

Category: Windows Risk factor: High Added: 31 Jan 2012
Synopsis:

The remote Windows host has ActiveX controls installed that could be abused to execute arbitrary code remotely.

Description:

Multiple ActiveX controls, installed on the remote Windows host as part of McAfee Security-as-a-Service (SaaS) / Total Protection
Service, are potentially affected by the following issues :

- A flaw in the MyAsUtil.dll ActiveX control can be exploited to execute arbitrary commands.

- A flaw in the myCIOScn.dll ActiveX control can be exploited to write arbitrary data to a file on the affected computer.

See also:

https://kc.mcafee.com/corporate/index?page=content&id=SB10016
http://dvlabs.tippingpoint.com/advisory/TPTI-11-12
http://dvlabs.tippingpoint.com/advisory/TPTI-11-13

Solution:

Upgrade to McAfee SaaS Endpoint Protection 5.2.2 or later.

Risk factor:

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)