McAfee ePolicy Orchestrator Server Remote Code Execution Vulnerability
10 Apr. 2012
Summary
McAfee ePolicy Orchestrator has been reported prone to a remote code execution vulnerability. The issue is reported to be triggered when certain HTTP POST requests are handled by the McAfee ePolicy Orchestrator server.
Vulnerable Systems:
*McAfee ePolicy Orchestrator 3.0 SP2a and prior
An attacker may exploit this issue to execute code in the context of the affected software, and distribute this code across ePolicy Orchestrator infrastructure.
Vendor Status:
McAfee as issued an update for this vulnerablity.