vendor:
ePolicy Orchestrator Agent
by:
Shashank Pandey a.k.a G0D_0F_z10N
7.5
CVSS
HIGH
Buffer Overflow
Not provided
CWE
Product Name: ePolicy Orchestrator Agent
Affected Version From: Not provided
Affected Version To: Not provided
Patch Exists: NO
Related CWE: Not provided
CPE: Not provided
Platforms Tested: Windows
Not provided
McAfee ePolicy Orchestrator Agent HTTP POST Buffer Mismanagement Vulnerability
The McAfee ePolicy Orchestrator agent has a buffer management vulnerability that can be exploited to crash the affected agent and potentially trigger a buffer overflow. The vulnerability exists due to insufficient sanitization of certain values in HTTP POST headers processed by the ePolicy Orchestrator.
Mitigation:
Patch has not been released