Check Point Reference: | CPAI-2006-230 |
Date Published: | 23 Feb 2010 |
Severity: | High |
Last Updated: | Tuesday 23 February, 2010 |
Source: | |
Industry Reference: | CVE-2006-3961 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | McAfee Corporation is a major vendor of numerous anti-virus, network, and desktop security products which are deployed in consumer as well as enterprise environments. The applications use several common components which are installed with the application. One of these components is the McAfee Security Center, which is responsible for managing virus updates, subscription licenses, and other functionality related to the overall configuration of the installed product. In the case where several applications are installed on the same machine, the Security Center can manage the relevant options for all such applications. There exists a stack buffer overflow vulnerability in McAfee's Subscription Manager ActiveX control, which is shipped with all Home and Home Business products. The issue is caused by insufficient checks of user supplied function arguments. An attacker may exploit this vulnerability to inject and execute arbitrary code in the security context of the currently logged in user. In a simple attack case, the application that embeds the affected ActiveX object, such as Internet Explorer, will be terminated abnormally. In a sophisticated attack scenario, where the malicious user is successful in injecting and executing supplied code, the behaviour of the system is dependent on the nature of the injected code. |
This protection will detect and block attempts to exploit this vulnerability.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: Security Products Enforcement Violation.
Attack Information: McAfee Subscription Manager ActiveX stack buffer overflow