Short Name |
APP:MCAFEE-EBUSINESS-RCE |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
McAfee E-Business Server Authentication Remote Code Execution |
Release Date |
2012/11/09 |
Update Number |
2202 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects attempts to exploit a known vulnerability against McAfee E-Business Server. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the affected application.
McAfee E-Business Server is prone to a remote code-execution vulnerability that occurs prior to authentication. Attackers can leverage this issue to execute arbitrary code with superuser privileges. Successful exploits will completely compromise affected computers. Failed attacks will cause denial-of-service conditions. E-Business Server 8.5.2 and prior versions are vulnerable. NOTE: This issue may be related to the issue described in BID 26269 (McAfee E-Business Server Authentication Packet Handling Integer Overflow Vulnerability).