Check Point Advisories

McAfee Subscription Manager ActiveX Stack Buffer Overflow (CVE-2006-3961)

Check Point Reference: CPAI-2006-230
Date Published: 23 Feb 2010
Severity: High
Last Updated: Tuesday 23 February, 2010
Source:
Industry Reference:CVE-2006-3961
Protection Provided by:

Security Gateway
R81, R80, R77, R75

Who is Vulnerable?
Vulnerability Description McAfee Corporation is a major vendor of numerous anti-virus, network, and desktop security products which are deployed in consumer as well as enterprise environments. The applications use several common components which are installed with the application. One of these components is the McAfee Security Center, which is responsible for managing virus updates, subscription licenses, and other functionality related to the overall configuration of the installed product. In the case where several applications are installed on the same machine, the Security Center can manage the relevant options for all such applications. There exists a stack buffer overflow vulnerability in McAfee's Subscription Manager ActiveX control, which is shipped with all Home and Home Business products. The issue is caused by insufficient checks of user supplied function arguments. An attacker may exploit this vulnerability to inject and execute arbitrary code in the security context of the currently logged in user. In a simple attack case, the application that embeds the affected ActiveX object, such as Internet Explorer, will be terminated abnormally. In a sophisticated attack scenario, where the malicious user is successful in injecting and executing supplied code, the behaviour of the system is dependent on the nature of the injected code.

Protection Overview

This protection will detect and block attempts to exploit this vulnerability.

In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.

Security Gateway R80 / R77 / R75

  1. In the IPS tab, click Protections and find the McAfee Subscription Manager ActiveX Stack Buffer Overflow protection using the Search tool and Edit the protection's settings.
  2. Install policy on all Security Gateways.

This protection's log will contain the following information:

Attack Name:  Security Products Enforcement Violation.
Attack Information:  McAfee Subscription Manager ActiveX stack buffer overflow

×
  Feedback
This website uses cookies for its functionality and for analytics and marketing purposes. By continuing to use this website, you agree to the use of cookies. For more information, please read our Cookies Notice.
OK