← Vulnerability feed

Vulnerability record · CVE-2000-1128 · published 9 January 2001

CVE-2000-1128: Mcafee virusscan vulnerability

MMcafee · Virusscan

The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.

4.6 CVSS 2.0 Medium EPSS 0.48% · top 61.4%
4.6CVSS 2.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

The default configuration of McAfee VirusScan 4.5 does not quote the ImagePath variable, which improperly sets the search path and allows local users to place a Trojan horse "common.exe" program in the C:\Program Files directory.

AV:L/AC:L/Au:N/C:P/I:P/A:P

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2000-1128 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2007-2584Mcafee security center vulnerabilityBuffer overflow in the IsOldAppInstalled function in the McSubMgr.McSubMgr Subscription Manager ActiveX control (MCSUBMGR.DLL) in McAfee SecurityCent…EPSS 9.7%7.2CVE-2004-0831Mcafee virusscan vulnerabilityMcAfee VirusScan 4.5.1 does not drop SYSTEM privileges before allowing users to browse for files via the "System Scan" properties of the System Tray …EPSS 0.39%7.2CVE-2000-0119Mcafee virusscan vulnerabilityThe default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED folder that is used by the W…EPSS 1.2%6.9CVE-2002-2282Mcafee virusscan vulnerabilityMcAfee VirusScan 4.5.1, when the WebScanX.exe module is enabled, searches for particular DLLs from the user's home directory, even when browsing the …EPSS 0.33%6.8CVE-2006-3961Mcafee antispyware memory buffer overflow vulnerabilityBuffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network S…EPSS 34%5.0CVE-2006-5417Mcafee internet security suite vulnerabilityMcAfee Network Agent (mcnasvc.exe) 1.0.178.0, as used by multiple McAfee products possibly including Internet Security Suite, Personal Firewall Plus,…EPSS 1.8%4.6CVE-2006-6474Mcafee virusscan vulnerabilityUntrusted search path vulnerability in McAfee VirusScan for Linux 4510e and earlier includes the current working directory in the DT_RPATH environmen…EPSS 0.41%2.1CVE-2006-3575Mcafee virusscan vulnerabilityUnknown vulnerability in the Buffer Overflow Protection in McAfee VirusScan Enterprise 8.0.0 allows local users to cause a denial of service (unstabl…EPSS 0.38%

Source: NIST National Vulnerability Database (record CVE-2000-1128), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.