McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
BID:28573
Info
McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
| Bugtraq ID: | 28573 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-1855 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 02 2008 12:00AM |
| Updated: | May 07 2015 05:30PM |
| Credit: | Mati Aharoni |
| Vulnerable: |
McAfee ProtectionPilot 1.5 McAfee ePolicy Orchestrator 3.6.1 patch 1 McAfee ePolicy Orchestrator 3.6.1 McAfee ePolicy Orchestrator 3.6 patch 5 McAfee ePolicy Orchestrator 3.6 McAfee ePolicy Orchestrator 4.0 McAfee Common Management Agent (CMA) 3.6 .574 McAfee Common Management Agent (CMA) 3.6 .546 McAfee Common Management Agent (CMA) 3.6 .453 McAfee Common Management Agent (CMA) 3.6 .438 McAfee Common Management Agent (CMA) 3.5.5 .438 McAfee Common Management Agent (CMA) 3.0.6 .453 |
| Not Vulnerable: | |
Discussion
McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
McAfee Common Management Agent is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users.
McAfee Common Management Agent is prone to a remote denial-of-service vulnerability.
Successfully exploiting this issue allows remote attackers to crash the affected application, denying further service to legitimate users.
Exploit / POC
McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
Solution:
The vendor released HotFix 10 to address this issue. Please see the references for more information.
Solution:
The vendor released HotFix 10 to address this issue. Please see the references for more information.
References
McAfee Common Management Agent 'FrameworkService.exe' Remote Denial of Service Vulnerability
References:
References:
- ePolicy Orchestrator Product Page (McAfee)
- McAfee Homepage (McAfee)
- McAfee Security Bulletin - CMA HTTP Request DoS vulnerability (McAfee)