McAfee fixes flaw in Mac antivirus software

News

McAfee fixes flaw in Mac antivirus software

SearchSecurity.com Staff
McAfee Inc. has repaired a flaw in its antivirus program for Mac OS X machines that attackers could exploit to bypass the malware scanner and gain elevated system privileges.

More on McAfee

McAfee: Malware all about ID theft

Microsoft releases Vista APIs to security vendors

Former McAfee official settles fraud charges
An issue exists with the default permissions and validation of specific files belonging to McAfee Virex 7.7 that may allow for local authenticated command execution, the Santa Clara, Calif.-based antivirus vendor said in an advisory

"The vulnerability is caused due to /Library/Application Support/Virex/VShieldExclude.txt having insecure permissions and being created insecurely," Danish vulnerability clearinghouse Secunia said in an advisory. "This can be exploited to create arbitrary files with escalated privileges via symlink attacks."

McAfee recommends that users apply the patch, which has been pushed to all its live update servers.


Email Alerts

Register now to receive ComputerWeekly.com IT-related news, guides and more, delivered to your inbox.
By submitting your personal information, you agree to receive emails regarding relevant products and special offers from TechTarget and its partners. You also agree that your personal information may be transferred and processed in the United States, and that you have read and agree to the Terms of Use and the Privacy Policy.
 

COMMENTS powered by Disqus  //  Commenting policy