CVE-2008-1855
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service crash) via a long invalid method in requests for the /spin//AVClient//AVClient.csp URI, a different vulnerability than CVE-2006-5274.
FrameworkService.exe en McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 y anteriores, usado por ePolicy Orchestrator (ePO) y ProtectionPilot (PrP), permite a atacantes remotos corromper la memoria y provocar una denegación de servico (caída del servicio CMA Framework) a través de un método largo inválido en una petición al URI /spin//AVClient//AVClient.csp. Vulnerabilidad distinta del CVE-2006-5274.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2008-04-16 CVE Reserved
- 2008-04-16 CVE Published
- 2024-08-07 CVE Updated
- 2024-08-07 First Exploit
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-399: Resource Management Errors
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://www.securitytracker.com/id?1019794 | Vdb Entry | |
http://www.vupen.com/english/advisories/2008/1122/references | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41597 | Vdb Entry | |
https://knowledge.mcafee.com/article/219/615324_f.SAL_Public.html | X_refsource_confirm |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/5343 | 2024-08-07 | |
http://www.offensive-security.com/0day/mcafee_again.py.txt | 2024-08-07 | |
http://www.securityfocus.com/bid/28573 | 2024-08-07 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29637 | 2017-09-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mcafee Search vendor "Mcafee" | Cma Search vendor "Mcafee" for product "Cma" | <= 3.6.0.574 Search vendor "Mcafee" for product "Cma" and version " <= 3.6.0.574" | - |
Affected
|