skip to main | skip to sidebar

Muts' Blog

Monday, October 02, 2006

McAfee Epolicy Orchestrator / ProtectionPilot Buffer Overflow

I've released a PoC exploit for McAfee Epolicy Orchestrator / ProtectionPilot last night.
This exploit was tested on Win2k SP4 / Win2k3 sp1.
McAfee were notified on the 14th July, and havn't managed to get it pacthed since.

Proof of concept exploit code is available at:
http://www.remote-exploit.org/exploits/mcafee_epolicy_source.pm

And a short article describing the exploit is available at :
http://www.remote-exploit.org/advisories/mcafee-epo.pdf
Posted by muts at 7:56 AM
Newer Post Older Post Home

Blog Archive

  • ►  2009 (4)
    • ►  May (1)
    • ►  March (1)
    • ►  January (2)
  • ►  2008 (3)
    • ►  December (1)
    • ►  July (1)
    • ►  June (1)
  • ►  2007 (6)
    • ►  December (2)
    • ►  September (1)
    • ►  April (2)
    • ►  February (1)
  • ▼  2006 (6)
    • ▼  October (2)
      • BackTrack v2.0 Public Beta Has Been Released!
      • McAfee Epolicy Orchestrator / ProtectionPilot Buff...
    • ►  September (1)
    • ►  May (3)

Videos

  • BackTrack 3 Teaser
  • WEP Fragmentation Attack
  • Cursed Animations

Exploits

  • MS IE XML 0day
  • DivX 6.6 SRT SEH overwrite
  • HP OpenView NNM 7.5.1
  • IBM Tivoli Storage Manager
  • IBM Tivoli Provisioning Manager
  • Microsoft HLP File heap Overflow
  • Multiple Word 2007 Vulnerabilities
  • Mcafee EPO / Protection Pilot
  • IBM Lotus Domino IMAP Pre Auth
  • Eudora Quallcom IMAP Pre Auth
  • HP OpenView NNM 7.5.1

Articles

  • McAfee ePo Buffer overflow
  • GlobalScape Buffer Overflow
  • Having Fun with Cisco Routers