Description
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) and possibly execute arbitrary code via an HTTP POST request with an invalid Content-Length value, possibly triggering a buffer overflow.
Affected products
- McAfee / epolicy_orchestrator3.6.0 – 3.6.0
Exploits & proofs of concept
- exploit-dbMcAfee ePolicy Orchestrator 1.x/2.x/3.0 Agent - POST Buffer Mismanagementby cyber_flash
Updated 18m ago · 8 sources