Vulnerabilities > CVE-2007-1498 - Remote Buffer Overflow vulnerability in Mcafee Epolicy Orchestrator and Protectionpilot

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
mcafee
critical
nessus

Summary

Multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy Orchestrator (ePO) before 3.6.1 Patch 1 and ProtectionPilot (PRP) before 1.5.0 HotFix allow remote attackers to execute arbitrary code via a long argument to the (1) ExportSiteList and (2) VerifyPackageCatalog functions, and (3) unspecified vectors involving a swprintf function call.

Nessus

NASL familyWindows
NASL idEPOLICY_ORCHESTRATOR_SITEMANAGER_ACTIVEX.NASL
descriptionThe version of the SiteManager ActiveX control included with McAfee ePolicy Orchestrator or ProtectionPilot and installed on the remote host reportedly contains several buffer overflows. If an attacker can trick a user on the affected host into visiting a specially crafted web page, this issue could be leveraged to execute arbitrary code on the host subject to the user
last seen2020-06-01
modified2020-06-02
plugin id24814
published2007-03-15
reporterThis script is Copyright (C) 2007-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/24814
titleePolicy Orchestrator SiteManager ActiveX Control Multiple Buffer Overflows

Saint

  • bid22952
    descriptionMcAfee ePolicy Orchestrator SiteManager ExportSiteList buffer overflow
    idweb_tool_epolicysmax
    osvdb33796
    titleepo_sitemanager_exportsitelist
    typeclient
  • bid22952
    descriptionMcAfee ePolicy Orchestrator SiteManager ActiveX buffer overflow
    idweb_tool_epolicysmax
    osvdb33796
    titleepo_sitemanager_verifypackagecatalog
    typeclient