← Vulnerability feed

Vulnerability record · CVE-2009-5118 · published 22 August 2012

CVE-2009-5118: Mcafee virusscan enterprise vulnerability

MMcafee · Virusscan Enterprise

Untrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, as demonstrated by scanning a document located on a remote share.

9.3 CVSS 2.0 High EPSS 1.6% · top 25.0%
9.3CVSS 2.0 base score
1.6%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Untrusted search path vulnerability in McAfee VirusScan Enterprise before 8.7i allows local users to gain privileges via a Trojan horse DLL in an unspecified directory, as demonstrated by scanning a document located on a remote share.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-5118 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.4CVE-2020-7267Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Linux prior to 2.0.3 Hotfix 2635000 allows local users to delete files th…EPSS 0.26%8.4CVE-2020-7266Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in McAfee VirusScan Enterprise (VSE) for Windows prior to 8.8 Patch 14 Hotfix 116778 allows local users to delete …EPSS 0.26%8.1CVE-2016-8023Mcafee virusscan enterprise improper authentication vulnerabilityAuthentication bypass by assumed-immutable data vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote u…EPSS 9.2%8.1CVE-2016-8024Mcafee virusscan enterprise vulnerabilityImproper neutralization of CRLF sequences in HTTP headers vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allow…EPSS 8.7%8.0CVE-2016-8020Mcafee virusscan enterprise code injection vulnerabilityImproper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authentica…EPSS 11%7.9CVE-2007-2152Mcafee virusscan enterprise vulnerabilityBuffer overflow in the On-Access Scanner in McAfee VirusScan Enterprise before 8.0i Patch 12 allows user-assisted remote attackers to execute arbitra…EPSS 2.6%7.8CVE-2019-3585Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability in Microsoft Windows client (McTray.exe) in McAfee VirusScan Enterprise (VSE) 8.8 prior to Patch 14 may allow loca…EPSS 0.28%7.8CVE-2020-7280Mcafee virusscan enterprise improper privilege management vulnerabilityPrivilege Escalation vulnerability during daily DAT updates when using McAfee Virus Scan Enterprise (VSE) prior to 8.8 Patch 15 allows local users to…EPSS 0.40%

Source: NIST National Vulnerability Database (record CVE-2009-5118), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.