CVE-2008-1357
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 6.2%
from disclosure to weapon0 days
Published on NVDMar 17
1st PoCMar 12
exploitation probability
6.2%top 7% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/31399⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://aluigi.altervista.org/adv/meccaffi-adv.txthttp://secunia.com/advisories/29337http://securityreason.com/securityalert/3748https://exchange.xforce.ibmcloud.com/vulnerabilities/41178https://knowledge.mcafee.com/article/234/615103_f.sal_public.htmlhttp://www.securityfocus.com/archive/1/489476/100/0/threadedhttp://www.securityfocus.com/bid/28228http://www.securitytracker.com/id?1019609http://www.vupen.com/english/advisories/2008/0866/references