Update Protection against McAfee ePolicy Orchestrator SiteManager Multiple Buffer Overflow Vulnerabilities
| Check Point Reference: | CPAI-2007-062 | |
| Date Published: | ||
| Severity: | ||
| Source: | Secunia Advisory: SA24466 | |
| Industry Reference(s): | CVE-2007-1498 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? McAfee ePolicy Orchestrator 3.5.0 (Patch 7 and prior) McAfee ePolicy Orchestrator 3.6.0 (Patch 5 and prior) McAfee ePolicy Orchestrator 3.6.1 McAfee Protection Pilot 1.1.1 (Patch 3 and prior) McAfee Protection Pilot 1.5.0 | ||
| Vulnerability Description Multiple vulnerabilities exist in the McAfee ePolicy Orchestrator (ePO), and the Protection Pilot products. McAfee ePolicy Orchestrator is a central management system to enforce and monitor system security. A remote attacker could exploit this issue by convincing a user to visit a specially crafted HTML documents or open a malicious web page. Successful exploitation could result in remote code execution on the target system once the malicious page is loaded. |
||
|
Update/Patch Available Apply patches: https://mysupport.mcafee.com/eservice_enu/start.swe |
|
|
Vulnerability Details The vulnerabilities are due to multiple boundary errors in the 'SiteManager.dll' ActiveX Control component. To trigger this flaw, an attacker can specially craft a malicious Web page that initiates the vulnerable ActiveX control with a malformed argument. Successful exploitation allows execution of arbitrary code on the vulnerable system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block the malformed ActiveX Controls. Depending on the traffic mix, activating this protection may result in performance degradation.
In order for the protection to be activated, update your VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
The Update released on May 13, 2007 includes the following protections:
Apple Mac OS X GIF Image Vulnerability (CPAI-2007-059)
Mercury Mail Transport System Data Vulnerability (CPAI-2007-060)
Multiple Symantec SupportSoft ActiveX Control Vulnerabilities (CPAI-2007-061)
McAfee ePolicy Orchestrator SiteManager Multiple Vulnerabilities (CPAI-2007-062)
Sun Java GIF Image Vulnerability (CPAI-2007-063)