← Vulnerability feed

Vulnerability record · CVE-2007-2152 · published 19 April 2007

CVE-2007-2152: Mcafee virusscan enterprise vulnerability

MMcafee · Virusscan Enterprise

Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.

7.9 CVSS 2.0 High EPSS 2.6% · top 15.2%
7.9CVSS 2.0 base score
2.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitrary code via a long filename containing multi-byte (Unicode) characters.

AV:A/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-2152 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.3CVE-2009-5118Mcafee virusscan enterprise vulnerabilityUntrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an uns…EPSS 1.6%8.4CVE-2020-7267Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files th…EPSS 0.26%8.4CVE-2020-7266Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete …EPSS 0.26%8.1CVE-2016-8023Mcafee virusscan enterprise improper authentication vulnerabilityAuthentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…EPSS 9.2%8.1CVE-2016-8024Mcafee virusscan enterprise vulnerabilityImproper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allow…EPSS 8.7%8.0CVE-2016-8020Mcafee virusscan enterprise code injection vulnerabilityImproper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…EPSS 11%7.8CVE-2019-3585Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow loca…EPSS 0.28%7.8CVE-2020-7280Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2007-2152), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.