« Volver al listado

CVE-2018-6690

Estado: ModificadaAlta (7.1)—

Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-6690",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "trellixpsirt@trellix.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 6.1,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 4.2,
        "exploitabilityScore": 1.8
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "trellixpsirt@trellix.com",
      "affectedData": [
        {
          "vendor": "McAfee",
          "product": "McAfee Application Control (MAC)",
          "versions": [
            {
              "status": "affected",
              "version": "8.0.0 HF 4",
              "versionType": "custom",
              "lessThanOrEqual": "8.0.0 HF 4"
            }
          ],
          "platforms": [
            "x86"
          ]
        }
      ]
    }
  ],
  "published": "2018-09-18T22:29:00.413",
  "references": [
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-674165.pdf",
      "source": "trellixpsirt@trellix.com"
    },
    {
      "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10250",
      "source": "trellixpsirt@trellix.com"
    },
    {
      "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-674165.pdf",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://kc.mcafee.com/corporate/index?page=content&id=SB10250",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-346"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Accessing, modifying, or executing executable files vulnerability in Microsoft Windows client in McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 and earlier allows authenticated users to execute arbitrary code via file transfer from external system."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad de acceso, modificación o ejecución de archivos ejecutables en el cliente Microsoft Windows en McAfee Application and Change Control (MACC) 8.0.0 Hotfix 4 y anteriores permite que usuarios autenticados ejecuten código arbitrario mediante la transferencia de archivos del sistema externo."
    }
  ],
  "lastModified": "2026-06-17T02:02:12.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AFB4AAA8-1FEA-4648-8D23-86ACA1865AE0",
              "versionEndIncluding": "7.0.2"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:8.0.0:-:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F49B3D91-C415-4475-AB0C-C8616EA1D618"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:8.0.0:hotfix1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F7855EC9-B8F2-4155-9801-5AE40CBC6F73"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:8.0.0:hotfix2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4F98D1F8-5EE8-43FB-A5D9-189D6C85D37E"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:8.0.0:hotfix3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "841EFE70-EEA2-41C2-B131-74EFA6F27E11"
            },
            {
              "criteria": "cpe:2.3:a:mcafee:application_change_control:8.0.0:hotfix4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "93402938-F29F-44D4-BBC5-0A25A363AB3C"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "trellixpsirt@trellix.com"
}