ActiveX Control Vulnerability in McAfee SaaS Endpoint Protection
CVE-2011-3006

Currently unrated

Key Information:

Vendor

Mcafee

Vendor
CVE Published:
10 August 2011

What is CVE-2011-3006?

The MyAsUtil ActiveX control in the McAfee SaaS Endpoint Protection software contains a vulnerability that allows remote attackers to bypass execution policies and execute arbitrary code through Cross-Site Scripting (XSS) attacks. This attack exploits the MyASUtil.SecureObjectFactory.CreateSecureObject method and can lead to significant security breaches by allowing unauthorized actions within the client's environment. Users of McAfee SaaS Endpoint Protection versions 5.2.1 and earlier are particularly at risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.