CVE-2012-4586: McAfee Email And Web Security
Low severity, CVSS 3.5. EPSS: 0.9% chance of exploitation in the next 30 days.
McAfee Email and Web Security (EWS) 5.x before 5.5 Patch 6 and 5.6 before Patch 3, and McAfee Email Gateway (MEG) 7.0 before Patch 1, accesses files with the privileges of the root user, which allows remote authenticated users to bypass intended permission settings by requesting a file.
Affected products
- McAfee Email And Web Security: version 5.0 only; version 5.5 only; version 5.6 only
- McAfee Email Gateway: version 7.0 only
Published 2012-08-22. Last modified 2026-06-16.