CVE-2006-3961 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 34.4% (pctl 98)
Patch early
A public exploit exists.
Description
Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 34.36% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-08-01 |
| Last modified | 2026-06-16 |
Affected (9)
| Vendor | Product |
|---|---|
| mcafee | antispyware |
| mcafee | internet security suite |
| mcafee | personal firewall plus |
| mcafee | privacy service |
| mcafee | quickclean |
| mcafee | security center |
| mcafee | spamkiller |
| mcafee | virusscan |
| mcafee | wireless home network security |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | McAfee Subscription Manager - Remote Stack Buffer Overflow (Metasploit) | 2010-07-03 |
References
- http://secunia.com/advisories/21264
- http://securitytracker.com/id?1016614
- http://ts.mcafeehelp.com/faq3.asp?docid=407052
- http://www.eeye.com/html/research/advisories/AD2006807.html
- http://www.eeye.com/html/research/upcoming/20060719.html
- http://www.kb.cert.org/vuls/id/481212
- http://www.osvdb.org/27698
- http://www.securityfocus.com/archive/1/442495/100/100/threaded
- http://www.securityfocus.com/bid/19265
- http://www.vupen.com/english/advisories/2006/3096
- http://secunia.com/advisories/21264
- http://securitytracker.com/id?1016614
- http://ts.mcafeehelp.com/faq3.asp?docid=407052
- http://www.eeye.com/html/research/advisories/AD2006807.html
- http://www.eeye.com/html/research/upcoming/20060719.html
- http://www.kb.cert.org/vuls/id/481212
- http://www.osvdb.org/27698
- http://www.securityfocus.com/archive/1/442495/100/100/threaded
- http://www.securityfocus.com/bid/19265
- http://www.vupen.com/english/advisories/2006/3096
→ the Explorer · watch your stack · NVD