Back

CVE-2005-4505

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA 3.5 (patch 5) might allow local users to gain privileges via a malicious "program.exe" file in the C: folder, which is run by naPrdMgr.exe when it attempts to execute EntVUtil.EXE under an unquoted "Program Files" path.

Published: Dec 23, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (2)

Vendor Product Version
mcafee common_management_agent 3.5
mcafee virusscan_enterprise 8.0i

GitHub Security Advisory GHSA-jx59-j4wf-4x4h

Unquoted Windows search path vulnerability in McAfee VirusScan Enterprise 8.0i (patch 11) and CMA...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 0.99%

Top 40% most likely to be exploited

Threat Score 29.1 / 100

Data Sources

NVD EPSS GitHub