← Vulnerability feed

Vulnerability record · CVE-2006-5156 · published 5 October 2006

CVE-2006-5156: McAfee ePolicy Orchestrator and ProtectionPilot buffer overflow via long source header

MMcafee · Epolicy Orchestrator

McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg/ carrying an overly long source header. The flaw allows remote code execution and affects the central management servers that many organizations use to administer endpoint security, so a compromise has broad downstream impact.

10.0 CVSS 2.0 High EPSS 74% · top 0.5%
10.0CVSS 2.0 base score
74%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
28References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityCVSS 2.0 base score is 10.0 with network reachability, no authentication and full confidentiality, integrity and availability impact, and public exploit references exist for a central management server.

What it is

McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 contain a buffer overflow reachable through a request to /spipe/pkg/ carrying an overly long source header. The flaw allows remote code execution and affects the central management servers that many organizations use to administer endpoint security, so a compromise has broad downstream impact.

Impact

A remote attacker can execute arbitrary code on the ePolicy Orchestrator or ProtectionPilot server, typically with the privileges of the affected service. Because these servers manage endpoint agents, control of the server can be leveraged to push policy or software to managed hosts.

Attack surface

The vulnerability is network reachable via an HTTP request to the /spipe/pkg/ path with a long source header, per the CVSS vector AV:N/AC:L/Au:N, meaning no authentication and no user interaction are required. The description does not state whether the endpoint is restricted to trusted networks, so exposure depends on how the server is deployed.

Exploitation

The record is not listed in CISA KEV, but EPSS is very high (0.73593 probability, 99.444 percentile) and references include an Exploit-tagged advisory and a SecurityFocus entry tagged Exploit and Patch, indicating public exploit material exists.

What to do

  • Upgrade ePolicy Orchestrator to 3.5.0.720 or later and ProtectionPilot to 1.1.1.126 or later using the vendor patches referenced in the record.
  • Restrict network access to the ePolicy Orchestrator/ProtectionPilot server and its /spipe/ interface to trusted management networks only.
  • Place the management server behind a reverse proxy or firewall rule set that rejects oversized or malformed source headers before they reach the service.
  • Monitor vendor advisories for this product line and apply subsequent security updates promptly, since the server is a high-value management target.
  • If immediate patching is not possible, isolate the server from untrusted networks and limit administrative access to required personnel.

Detection

  • Inspect web and proxy logs for requests to /spipe/pkg/ with unusually long or malformed source headers.
  • Alert on crashes or restarts of the ePolicy Orchestrator/ProtectionPilot service that correlate with inbound HTTP requests.
  • Monitor for unexpected child processes or outbound connections originating from the management server after suspicious /spipe/ requests.
  • Review server logs for anomalous administrative activity or policy changes that could indicate post-exploitation use of the management console.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://download.nai.com/products/patches/ePO/v3.5/EPO3506.txt Patch
http://download.nai.com/products/patches/protectionpilot/v1.1.1/PRP1113.txt Patch
http://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&externalId=8611438&sliceId=SAL_Public&dialogI Patch
http://knowledge.mcafee.com/article/365/8611438_f.SAL_Public.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049803.html
http://secunia.com/advisories/22222 Vendor Advisory
http://securitytracker.com/id?1016970
http://securitytracker.com/id?1016971
http://www.kb.cert.org/vuls/id/842452 US Government Resource
http://www.osvdb.org/29421
http://www.remote-exploit.org/advisories/mcafee-epo.pdf Exploit
http://www.securityfocus.com/bid/20288 ExploitPatch
http://www.vupen.com/english/advisories/2006/3861
https://exchange.xforce.ibmcloud.com/vulnerabilities/29307
http://download.nai.com/products/patches/ePO/v3.5/EPO3506.txt Patch
http://download.nai.com/products/patches/protectionpilot/v1.1.1/PRP1113.txt Patch
http://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&docType=kc&externalId=8611438&sliceId=SAL_Public&dialogI Patch
http://knowledge.mcafee.com/article/365/8611438_f.SAL_Public.html
http://lists.grok.org.uk/pipermail/full-disclosure/2006-October/049803.html
http://secunia.com/advisories/22222 Vendor Advisory
http://securitytracker.com/id?1016970
http://securitytracker.com/id?1016971
http://www.kb.cert.org/vuls/id/842452 US Government Resource
http://www.osvdb.org/29421
http://www.remote-exploit.org/advisories/mcafee-epo.pdf Exploit
http://www.securityfocus.com/bid/20288 ExploitPatch
http://www.vupen.com/english/advisories/2006/3861
https://exchange.xforce.ibmcloud.com/vulnerabilities/29307

Track CVE-2006-5156 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2016-8027Mcafee epolicy orchestrator sql injection vulnerabilitySQL injection vulnerability in core services in Intel Security McAfee ePolicy Orchestrator (ePO) 5.3.2 and earlier and 5.1.3 and earlier allows attac…EPSS 5.7%10.0CVE-2002-0690Mcafee epolicy orchestrator vulnerabilityFormat string vulnerability in McAfee Security ePolicy Orchestrator (ePO) 2.5.1 allows remote attackers to execute arbitrary code via an HTTP GET req…EPSS 8.4%9.8CVE-2017-3936Mcafee epolicy orchestrator os command injection vulnerabilityOS Command Injection vulnerability in McAfee ePolicy Orchestrator (ePO) 5.9.0, 5.3.2, 5.3.1, 5.1.3, 5.1.2, 5.1.1, and 5.1.0 allows attackers to run a…EPSS 1.4%9.3CVE-2007-1498Mcafee epolicy orchestrator vulnerabilityMultiple stack-based buffer overflows in the SiteManager.SiteMgr.1 ActiveX control (SiteManager.dll) in the ePO management console in McAfee ePolicy …EPSS 7.7%8.8CVE-2019-3604Mcafee epolicy orchestrator cross-site request forgery vulnerabilityCross-Site Request Forgery (CSRF) vulnerability in McAfee ePO (legacy) Cloud allows unauthenticated users to perform unintended ePO actions using an …EPSS 0.44%8.3CVE-2015-8765Mcafee epolicy orchestrator vulnerabilityIntel McAfee ePolicy Orchestrator (ePO) 4.6.9 and earlier, 5.0.x, 5.1.x before 5.1.3 Hotfix 1106041, and 5.3.x before 5.3.1 Hotfix 1106041 allow remo…EPSS 2.7%8.1CVE-2020-2604Oracle commerce experience manager deserialization of untrusted data vulnerabilityVulnerability in the Java SE, Java SE Embedded product of Oracle Java SE (component: Serialization). Supported versions that are affected are Java SE…EPSS 4.9%8.0CVE-2023-5444Mcafee epolicy orchestrator cross-site request forgery vulnerabilityA Cross Site Request Forgery vulnerability in ePolicy Orchestrator prior to 5.10.0 CP1 Update 2 allows a remote low privilege user to successfully ad…EPSS 0.35%

Source: NIST National Vulnerability Database (record CVE-2006-5156), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.