HTTP: McAfee ePolicy Orchestrator SiteManager Exploit
This signature detects attempts to exploit a known vulnerability against McAfee ePolicy Orchestrator SiteManager. An attacker can create malicious Web pages, which if visited by a victim, can lead to the attacker gaining control of the victim's client browser.
Extended Description
The SiteManager.DLL ActiveX control shipped with McAfee EPolicy Orchestrator is prone to multiple buffer-overflow vulnerabilities. The software fails to perform sufficient bounds-checking of user-supplied input before copying it to an insufficiently sized memory buffer. Various versions of McAfee EPolicy Orchestrator and ProtectionPilot are vulnerable to these issues.
Affected Products
Mcafee epolicy_orchestrator
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Mcafee
9.3