VYPR
Unrated severityNVD Advisory· Published Dec 21, 2005· Updated Apr 16, 2026

CVE-2005-3657

CVE-2005-3657

Description

The ActiveX control in MCINSCTL.DLL for McAfee VirusScan Security Center does not use the IObjectSafetySiteLock API to restrict access to required domains, which allows remote attackers to create or append to arbitrary files via the StartLog and AddLog methods in the MCINSTALL.McLog object.

Affected products

12
  • cpe:2.3:a:mcafee:mcinsctl.dll:4.0.0.83:*:*:*:*:*:*:*
  • cpe:2.3:a:mcafee:virusscan_security_center:*:*:*:*:*:*:*:*+ 10 more
    • cpe:2.3:a:mcafee:virusscan_security_center:*:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:4.0.3:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:4.5:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:4.5.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:5.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:6.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:7.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:7.1:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:8.0:*:*:*:*:*:*:*
    • cpe:2.3:a:mcafee:virusscan_security_center:9.0:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

6

News mentions

0

No linked articles in our index yet.