5.4
CVSSv2

CVE-2008-1357

Published: 17/03/2008 Updated: 11/10/2018
CVSS v2 Base Score: 5.4 | Impact Score: 6.9 | Exploitability Score: 4.9
VMScore: 545
Vector: AV:N/AC:H/Au:N/C:N/I:N/A:C

Vulnerability Summary

Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and previous versions, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote malicious users to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.

Vulnerable Product Search on Vulmon Subscribe to Product

mcafee cma 3.6.574

mcafee epolicy orchestrator 4.0

mcafee cma 3.5.5.438

mcafee cma 3.6.438

mcafee agent 4.0

mcafee cma 3.0.6.453

mcafee mcafee framework 3.6.569

mcafee cma 3.6.453

mcafee cma 3.6.546

Exploits

source: wwwsecurityfocuscom/bid/28228/info McAfee Framework is prone to a remote format-string vulnerability Exploiting this issue will allow attackers to execute arbitrary code with the permissions of the framework or of an application that uses the framework Failed attacks will likely cause denial-of-service conditions McAfee Common ...