Intrusion detection and prevention systems provider Internet Security Systems (ISS) issued a “protection advisory” targeting older versions of McAfee’s anti-virus software engine last Thursday. Attackers are able to trigger a stack overflow within the process importing the McAfee AntiVirus Library, according to ISS.
This vulnerability can be triggered by an unauthenticated remote attacker without user interaction.
McAfee Security Flaw Highlights Need for Updates
Posted by: Jennifer LeClaire March 21, 2005 08:19 AMIntrusion detection and prevention systems provider Internet Security Systems (ISS) issued a “protection advisory” targeting older versions of McAfee’s anti-virus software engine last Thursday. Attackers are able to trigger a stack overflow within the process importing the McAfee AntiVirus Library, according to ISS.
This vulnerability can be triggered by an unauthenticated remote attacker without user interaction.