CVE-2005-4505

McAfee VirusScan Enterprise 8.0i-CMA 3.5 - Privilege Escalation

Title source: llm

Description

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Reed Arvin · clocalwindows
https://www.exploit-db.com/exploits/26970

Scores

EPSS 0.0022
EPSS Percentile 43.9%

Details

Status published
Products (2)
mcafee/common_management_agent 3.5 p5
mcafee/virusscan_enterprise 8.0i p11
Published Dec 23, 2005
Tracked Since Feb 18, 2026