CVE-2008-1855

McAfee CMA 3.6.0.574 - Memory Corruption

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-1855. PoCs published by muts.

AI-analyzed exploit summary This exploit targets a denial-of-service (DoS) vulnerability in McAfee EPO 4.0 by sending malformed HTTP requests with oversized buffers to the FrameworkService.exe on port 8081. The repeated requests aim to crash the service by overwhelming it.

Description

FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestrator (ePO) and ProtectionPilot (PrP), allows remote attackers to corrupt memory and cause a denial of service (CMA Framework service crash) via a long invalid method in requests for the /spin//AVClient//AVClient.csp URI, a different vulnerability than CVE-2006-5274.

Exploits (1)

exploitdb WORKING POC VERIFIED
by muts · pythondoswindows
https://www.exploit-db.com/exploits/5343

This exploit targets a denial-of-service (DoS) vulnerability in McAfee EPO 4.0 by sending malformed HTTP requests with oversized buffers to the FrameworkService.exe on port 8081. The repeated requests aim to crash the service by overwhelming it.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: McAfee EPO 4.0
No auth needed
Prerequisites: Network access to the target's port 8081
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28573
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/1122/references
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1019794
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29637
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41597
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/5343

Scores

EPSS 0.0757
EPSS Percentile 93.7%

Details

CWE
CWE-399
Status published
Products (1)
mcafee/cma < 3.6.0.574
Published Apr 16, 2008
Tracked Since Feb 18, 2026