CVE-2006-3961
50Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 34%
from disclosure to weapon1432 days
Published on NVDAug 1
1st PoC+1432d
metasploitAug 1
exploitation probability
34%top 2% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.
Affected products
n/a · n/apublic PoCs found — 1
exploitdbwww.exploit-db.com/exploits/16510unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://secunia.com/advisories/21264http://securitytracker.com/id?1016614http://ts.mcafeehelp.com/faq3.asp?docid=407052http://www.eeye.com/html/research/advisories/AD2006807.htmlhttp://www.eeye.com/html/research/upcoming/20060719.htmlhttp://www.kb.cert.org/vuls/id/481212http://www.osvdb.org/27698http://www.securityfocus.com/archive/1/442495/100/100/threadedhttp://www.securityfocus.com/bid/19265http://www.vupen.com/english/advisories/2006/3096