Remote Bypass Vulnerability in McAfee Antivirus Products
CVE-2009-1348
Currently unrated
Key Information:
- Vendor
Mcafee
- Vendor
- CVE Published:
- 30 April 2009
What is CVE-2009-1348?
A remote code execution bypass vulnerability exists in various McAfee antivirus products due to improper handling of fields in malformed RAR and ZIP archives. Attackers can exploit this weakness to evade virus detection, effectively allowing them to introduce malicious files onto vulnerable systems. The flaw stems from the handling of the Headflags, Packsize, and Filelength fields, which can be manipulated in crafted files, posing significant risks to users and organizations relying on these security products.