PT-2007-2890 · Mcafee+1 · Mcafee Epolicy Orchestrator+1

Published

2007-03-16

·

Updated

2011-03-08

·

CVE-2007-1498

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions McAfee ePolicy Orchestrator (ePO) versions prior to 3.6.1 Patch 1 ProtectionPilot (PRP) versions prior to 1.5.0 HotFix
Description The issue concerns multiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control. This can be exploited by remote attackers to execute arbitrary code via a long argument to the ExportSiteList and VerifyPackageCatalog functions, as well as through unspecified vectors involving a swprintf function call.
Recommendations For McAfee ePolicy Orchestrator (ePO) versions prior to 3.6.1 Patch 1, update to version 3.6.1 Patch 1 or later. For ProtectionPilot (PRP) versions prior to 1.5.0 HotFix, apply the 1.5.0 HotFix. As a temporary workaround, consider restricting access to the SiteManager.SiteMgr.1 ActiveX control until a patch is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1498

Affected Products

Mcafee Epolicy Orchestrator
Protectionpilot