Bypassing DEP and ASLR Protection Mechanisms in McAfee VirusScan Enterprise

Bypassing DEP and ASLR Protection Mechanisms in McAfee VirusScan Enterprise

CVE-2015-8577 · LOW Severity

AV:L/AC:H/AU:N/C:P/I:P/A:N

The Buffer Overflow Protection (BOP) feature in McAfee VirusScan Enterprise before 8.8 Patch 6 allocates memory with Read, Write, Execute (RWX) permissions at predictable addresses on 32-bit platforms when protecting another application, which allows attackers to bypass the DEP and ASLR protection mechanisms via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.