Vulnerability record · CVE-2006-5156 · published 5 October 2006
CVE-2006-5156: McAfee ePolicy Orchestrator and ProtectionPilot buffer overflow via long source header
MMcafee · Epolicy Orchestrator
McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg/ carrying an overly long source header. The flaw allows remote code execution and affects the central management servers that many organizations use to administer endpoint security, so a compromise has broad downstream impact.
Description
Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 base score is 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, and public exploit references exist for a central management server.
What it is
McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg/ carrying an overly long source header. The flaw allows remote code execution and affects the central management servers that many organizations use to administer endpoint security, so a compromise has broad downstream impact.
Impact
A remote attacker can execute arbitrary code on the ePolicy Orchestrator or ProtectionPilot server, typically with the privileges of the affected service. Because these servers manage endpoint agents, control of the server can be leveraged to push policy or software to managed hosts.
Attack surface
The vulnerability is network reachable via an HTTP request to the /spipe/pkg/ path with a long source header, per the CVSS vector AV:N/AC:L/Au:N, meaning no authentication and no user interaction are required. The description does not state whether the endpoint is restricted to trusted networks, so exposure depends on how the server is deployed.
Exploitation
The record is not listed in CISA KEV, but EPSS is very high (0.73593 probability, 99.444 percentile) and references include an Exploit-tagged advisory and a SecurityFocus entry tagged Exploit and Patch, indicating public exploit material exists.
What to do
- Upgrade ePolicy Orchestrator to 3.5.0.720 or later and ProtectionPilot to 1.1.1.126 or later using the vendor patches referenced in the record.
- Restrict network access to the ePolicy Orchestrator/ProtectionPilot server and its /spipe/ interface to trusted management networks only.
- Place the management server behind a reverse proxy or firewall rule set that rejects oversized or malformed source headers before they reach the service.
- Monitor vendor advisories for this product line and apply subsequent security updates promptly, since the server is a high-value management target.
- If immediate patching is not possible, isolate the server from untrusted networks and limit administrative access to required personnel.
Detection
- Inspect web and proxy logs for requests to /spipe/pkg/ with unusually long or malformed source headers.
- Alert on crashes or restarts of the ePolicy Orchestrator/ProtectionPilot service that correlate with inbound HTTP requests.
- Monitor for unexpected child processes or outbound connections originating from the management server after suspicious /spipe/ requests.
- Review server logs for anomalous administrative activity or policy changes that could indicate post-exploitation use of the management console.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-5156 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-5156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.