CVE-2008-1357 EXPLOIT
5.4
MEDIUM · CVSS 2.0 · EPSS 6.2% (pctl 93)
Patch early
A public exploit exists.
Description
Format string vulnerability in the logDetail function of applib.dll in McAfee Common Management Agent (CMA) 3.6.0.574 (Patch 3) and earlier, as used in ePolicy Orchestrator 4.0.0 build 1015, allows remote attackers to cause a denial of service (crash) or execute arbitrary code via format string specifiers in a sender field in an AgentWakeup request to UDP port 8082. NOTE: this issue only exists when the debug level is 8.
Scoring
| CVSS | 5.4 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:H/Au:N/C:N/I:N/A:C |
| EPSS | 6.2% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-134 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-03-17 |
| Last modified | 2026-06-16 |
Affected (4)
| Vendor | Product |
|---|---|
| mcafee | agent |
| mcafee | cma |
| mcafee | epolicy orchestrator |
| mcafee | mcafee framework |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | McAfee Framework ePolicy 3.x - Orchestrator '_naimcomn_Log' Remote Format String | 2008-03-12 |
References
- http://aluigi.altervista.org/adv/meccaffi-adv.txt
- http://secunia.com/advisories/29337
- http://securityreason.com/securityalert/3748
- http://www.securityfocus.com/archive/1/489476/100/0/threaded
- http://www.securityfocus.com/bid/28228
- http://www.securitytracker.com/id?1019609
- http://www.vupen.com/english/advisories/2008/0866/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41178
- https://knowledge.mcafee.com/article/234/615103_f.sal_public.html
- http://aluigi.altervista.org/adv/meccaffi-adv.txt
- http://secunia.com/advisories/29337
- http://securityreason.com/securityalert/3748
- http://www.securityfocus.com/archive/1/489476/100/0/threaded
- http://www.securityfocus.com/bid/28228
- http://www.securitytracker.com/id?1019609
- http://www.vupen.com/english/advisories/2008/0866/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41178
- https://knowledge.mcafee.com/article/234/615103_f.sal_public.html
→ the Explorer · watch your stack · NVD