***** NSEC Information Service – McAfee *****
Datum: 2012-05-04
McAfee bekräftar en sårbarhet i McAfee Virtual Technician (MVT). Se bulletin från McAfee nedan.
McAfee confirms a vulnerability in the McAfee Virtual Technician (MVT) tool and McAfee ePO-MVT. This vulnerability allows an attacker to bypass Internet Explorer browser security settings to remotely execute operating system commands. An Internet Explorer script can also be created to remotely crash the browser by specifying an arbitrary memory address. It is possible for a malicious website to exploit the MVT vulnerability and run malicious code.
DESCRIPTION: McAfee Virtual Technician (MVT) and McAfee ePO MVT are free tools that will scan a system to ensure that the McAfee products are installed correctly. This tool will identify possible problems and help resolve problems detected during a check-up process. NOTE: The MVT tool is not tied to a particular McAfee product. Any system could have MVT installed; potentially even those systems which have uninstalled their McAfee products.
Remediation for MVT
McAfee has updated the MVT program. Customers can access MVT in their Programs menu and run the MVT program to automatically update to the latest patched version. If users previously uninstalled the program, they can simply access the McAfee website at http://mvt.mcafee.com/mvt to run MVT and install an updated version of the tool.
Resolution for ePO-MVT
1. For immediate protection, ePO-MVT users are urged to uninstall the program via the ePO console. See PD22556, ePO-MVT Walkthrough Guide for uninstall instructions (https://kc.mcafee.com/corporate/index?page=content&id=PD22556)
2. The updated version of ePO-MVT is expected to be ready in 72 hours. An SNS email will go out to subscribers when the download is available.
For more information, see SB10028, https://kc.mcafee.com/corporate/index?page=content&id=SB10028
mvh
NIS
NSEC Network Security