Files
CVEs-PoC/2012/CVE-2012-4586.md
2025-09-29 21:09:30 +02:00

18 lines
780 B
Markdown

### [CVE-2012-4586](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4586)
![](https://img.shields.io/static/v1?label=Product&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=n%2Fa&color=brightgreen)
### Description
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
### POC
#### Reference
- https://kc.mcafee.com/corporate/index?page=content&id=SB10020
#### Github
No PoCs found on GitHub currently.