McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
BID:20288
Info
McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 20288 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 02 2006 12:00AM |
| Updated: | Oct 05 2006 06:30PM |
| Credit: | BackTrack Development Team discovered this vulnerability. |
| Vulnerable: |
McAfee ProtectionPilot 1.1.1 patch 2 McAfee ProtectionPilot 1.1.1 McAfee ProtectionPilot 1.1 McAfee ePolicy Orchestrator 3.0 SP2a McAfee ePolicy Orchestrator 3.0 McAfee ePolicy Orchestrator 2.5.1 McAfee ePolicy Orchestrator 2.5 SP1 McAfee ePolicy Orchestrator 2.5 McAfee ePolicy Orchestrator 2.0 McAfee ePolicy Orchestrator 1.1 McAfee ePolicy Orchestrator 1.0 McAfee ePolicy Orchestrator 3.5 patch 5 McAfee ePolicy Orchestrator 3.5 |
| Not Vulnerable: |
McAfee ProtectionPilot 1.1.1 patch 3 McAfee ePolicy Orchestrator 3.5 patch 6 |
Discussion
McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
The HTTP server component of McAfee ePolicy Orchestrator and ProtectionPilot is prone to a remote stack-based buffer-overflow vulnerability that can lead to complete system compromise.
This issue arises because the application fails to perform boundary checks before copying user-supplied data into sensitive process buffers.
A successful attack may result in arbitrary code execution with SYSTEM privileges, leading to a full compromise.
McAfee ePolicy Orchestrator 3.5.0 patch 5 and prior versions as well as ProtectionPilot 1.1.1 patch 2 and prior versions are vulnerable to this issue.
The HTTP server component of McAfee ePolicy Orchestrator and ProtectionPilot is prone to a remote stack-based buffer-overflow vulnerability that can lead to complete system compromise.
This issue arises because the application fails to perform boundary checks before copying user-supplied data into sensitive process buffers.
A successful attack may result in arbitrary code execution with SYSTEM privileges, leading to a full compromise.
McAfee ePolicy Orchestrator 3.5.0 patch 5 and prior versions as well as ProtectionPilot 1.1.1 patch 2 and prior versions are vulnerable to this issue.
Exploit / POC
McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
A Metasploit exploit module is available. It reportedly works against Windows 2000 SP4, Windows 2000 SP1, and Windows 2003 SP1.
A Python proof-of-concept program is also available.
A Metasploit exploit module is available. It reportedly works against Windows 2000 SP4, Windows 2000 SP1, and Windows 2003 SP1.
A Python proof-of-concept program is also available.
Solution / Fix
McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for more information.
Solution:
The vendor has released an advisory along with fixes to address this issue. Please see the referenced advisory for more information.
References
McAfee EPolicy Orchestrator and ProtectionPilot HTTP Server Remote Buffer Overflow Vulnerability
References:
References:
- McAfee Epolicy 3.5.0 / Protection Pilot 1.1.0 (BackTrack Development Team)
- McAfee ePolicy Orchestrator / ProtPilot Source Overflow (HD Moore)
- McAfee HTTP Server vulnerable to buffer overflow (US-CERT)
- McAfee Security Bulletin - ePolicy Orchestrator (ePO) 3.5 Patch 6 or higher / Pr (McAfee)
- Vendor Customer Support Website (McAfee)
- Vendor Home Page (McAfee)