First published: Sat Oct 05 2013(Updated: )
FrameworkService.exe in McAfee Framework Service in McAfee Managed Agent (MA) before 4.5.0.1927 and 4.6 before 4.6.0.3258 allows remote attackers to cause a denial of service (service crash) via a malformed HTTP request.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
McAfee Agent | >=4.5.0<4.5.0.1927 | |
McAfee Agent | >=4.6.0<4.6.0.3258 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-3627 is classified as a denial of service vulnerability that can potentially crash the McAfee Framework Service.
To address CVE-2013-3627, upgrade the McAfee Managed Agent to version 4.5.0.1927 or later, or version 4.6.0.3258 or later.
CVE-2013-3627 affects McAfee Managed Agent versions prior to 4.5.0.1927 and 4.6 before 4.6.0.3258.
CVE-2013-3627 can be exploited by remote attackers sending malformed HTTP requests that lead to a denial of service.
Using McAfee Managed Agent versions prior to the patch for CVE-2013-3627 poses a security risk as they are vulnerable to denial of service attacks.