SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-3961

Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean…

MEDIUM 6.8EPSS 34.4%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 34.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.

CVSS 2.0
6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS
34.36% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
mcafee/antispyware · mcafee/internet security suite · mcafee/personal firewall plus · mcafee/privacy service · mcafee/quickclean · mcafee/security center · mcafee/spamkiller · mcafee/virusscan · mcafee/wireless home network security
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.