← Vulnerability feed

Vulnerability record · CVE-2005-4505 · published 23 December 2005

CVE-2005-4505: Mcafee common management agent vulnerability

MMcafee · Common Management Agent

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

7.2 CVSS 2.0 High EPSS 0.99% · top 39.1%
7.2CVSS 2.0 base score
0.99%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

AV:L/AC:L/Au:N/C:C/I:C/A:C

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-4505 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-5118Mcafee virusscan enterprise vulnerabilityUntrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an uns…EPSS 1.6%8.4CVE-2020-7267Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files th…EPSS 0.26%8.4CVE-2020-7266Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete …EPSS 0.26%8.1CVE-2016-8023Mcafee virusscan enterprise improper authentication vulnerabilityAuthentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…EPSS 9.2%8.1CVE-2016-8024Mcafee virusscan enterprise vulnerabilityImproper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allow…EPSS 8.7%8.0CVE-2016-8020Mcafee virusscan enterprise code injection vulnerabilityImproper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…EPSS 11%7.9CVE-2007-2152Mcafee virusscan enterprise vulnerabilityBuffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitra…EPSS 2.6%7.8CVE-2019-3585Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow loca…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2005-4505), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.