peter bassill · operator
$ cve CVE-2008-1855 JSON

CVE-2008-1855 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 7.6% (pctl 94)

Patch early

A public exploit exists.

Description

FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service crash) via a long invalid method in requests for the /spin//AVClient//AVClient.csp URI, a different vulnerability than CVE-2006-5274.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
EPSS7.58% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-399
On CISA KEVno
Public exploityes
Published2008-04-16
Last modified2026-06-16

Affected (1)

VendorProduct
mcafeecma

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD