This is a read-only archive. No new posts or registrations. Privacy Page
Discussion

McAfee ePolicy Orchestrator Vuln - update available

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

FYI…

- http://secunia.com/advisories/21037/
Release Date: 2006-07-14
Critical: Moderately critical
Impact: Security Bypass, System access
Where: From local network
Solution Status: Vendor Patch
Software: McAfee ePolicy Orchestrator 3.x *
…The vulnerability is caused due to an input validation error in the management console's Framework Service component (enabled by default on all servers and agents)… The vulnerability has been reported in version 3.5.0.x. Prior versions may also be affected.
Solution:
Update to version 3.5.5 or later.
https://secure.nai.com/us/forms/downloads/upgrades/login.asp …"

* http://www.mcafee.com/us/enterprise/produc…chestrator.html
"McAfee® ePolicy Orchestrator® is a security management solution that gives you a coordinated defense against malicious threats and attacks… It enables your administrators to handle enterprise-wide protection using anti-virus, anti-spyware, system firewalls, host IPS, and content filtering…"

:ph34r:
FYI…

- http://apnews.myway.com/article/20060714/D8IS11MG5.html
July 14, 2006
"…McAfee Inc., fixed a dangerous design flaw months ago in its flagship technology for managing protective software in large organizations but did not warn businesses and U.S. government agencies until Friday. McAfee issued a rare apology and urged customers to install updated versions of its software immediately. McAfee's antivirus software is used by more than one-third of corporations in the United States and Europe… The design flaw affects a component in McAfee's "ePolicy Orchestrator", used for managing security software on tens of thousands of computers across large organizations. The Defense Department announced last month it has selected the technology from Santa Clara, Calif.-based McAfee to run its computer-intrusion-prevention systems worldwide… Consumer versions of McAfee's security software, sold at retail outlets around the country, were not affected because - unlike corporate versions - they do not depend on McAfee's centralized management tool for updates to protect against the newest viruses and other threats…"

:oops:
FYI…

- http://isc.sans.org/diary.php?storyid=1489
Last Updated: 2006-07-17 23:28:47 UTC
"eEye** claims that the vulnerability allows for remote code execution as SYSTEM, McAfee seems to be saying it only allows for placement of arbitrary files on the vulnerable host. McAfee is acknowledging the vulnerability in their EPO product, and have posted a fix*.

Update 3.5.5.438 or higher fixes vuln
* http://knowledge.mcafee.com/article/640/99…SAL_Public.html

** http://www.eeye.com/html/research/advisories/AD20060713.html

:mellow: