CVE-2012-4593: McAfee Application Control

Medium severity, CVSS 5.0. EPSS: 1% chance of exploitation in the next 30 days.

McAfee Application Control and Change Control 5.1.x and 6.0.0 do not enforce an intended password requirement in certain situations involving attributes of the password file, which allows local users to bypass authentication by executing a command.

Affected products

  • McAfee Application Control: version 5.1.0 only; version 5.1.1 only; version 5.1.2 only; version 6.0.0 only
  • McAfee Change Control: version 5.1.0 only; version 5.1.1 only; version 5.1.2 only; version 6.0.0 only

Published 2012-08-22. Last modified 2026-06-16.