CVE-2003-0616: High severity McAfee ePolicy Orchestrator vulnerability
Format string vulnerability in ePO service for McAfee ePolicy Orchestrator 2.0, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code via a POST request with format strings in the computerlist parameter, which are used when logging a failed name resolution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2003-0616?
CVE-2003-0616 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2003-0616?
To fix CVE-2003-0616, ensure that you upgrade to the latest version of McAfee ePolicy Orchestrator, specifically version 2.5.1 or later.
Who is affected by CVE-2003-0616?
CVE-2003-0616 affects users of McAfee ePolicy Orchestrator versions 2.0, 2.5, and 2.5.1.
What type of attack is facilitated by CVE-2003-0616?
CVE-2003-0616 facilitates remote code execution attacks via a crafted POST request.
What component of McAfee software is vulnerable in CVE-2003-0616?
The ePO service component of McAfee ePolicy Orchestrator is vulnerable in CVE-2003-0616.