← Vulnerability feed

Vulnerability record · CVE-2007-0446 · published 8 February 2007

CVE-2007-0446: HP Mercury LoadRunner Agent mchan.dll Stack Buffer Overflow

Hp · Mercury Loadrunner Agent

A stack-based buffer overflow exists in mchan.dll, reachable through magentproc.exe in HP Mercury LoadRunner Agent, Performance Center Agent, and Monitor over Firewall. A remote attacker can send a packet containing an overly long server_ip_name field to TCP port 54345 to trigger the overflow. Successful exploitation allows arbitrary code execution on the affected host.

10.0 CVSS 2.0 High EPSS 45% · top 1.3%
10.0CVSS 2.0 base score
45%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
26References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in magentproc.exe for Hewlett-Packard Mercury LoadRunner Agent 8.0 and 8.1, Performance Center Agent 8.0 and 8.1, and Monitor over Firewall 8.1 allows remote attackers to execute arbitrary code via a packet with a long server_ip_name field to TCP port 54345, which triggers the overflow in mchan.dll.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete confidentiality, integrity, and availability impact, combined with a high EPSS percentile, makes this a top remediation priority.

What it is

A stack-based buffer overflow exists in mchan.dll, reachable through magentproc.exe in HP Mercury LoadRunner Agent, Performance Center Agent, and Monitor over Firewall. A remote attacker can send a packet containing an overly long server_ip_name field to TCP port 54345 to trigger the overflow. Successful exploitation allows arbitrary code execution on the affected host.

Impact

An unauthenticated remote attacker can execute arbitrary code with the privileges of the vulnerable agent process, potentially leading to full host compromise. Because the agent typically runs with elevated privileges, the impact can extend to the underlying system.

Attack surface

The flaw is reached over the network via TCP port 54345 by sending a crafted packet with a long server_ip_name field; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/Au:N).

Exploitation

The record is not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.44702, 98.7th percentile) and a Zero Day Initiative advisory exists, indicating public technical detail and elevated likelihood of exploitation.

What to do

  • Apply the vendor patch or upgrade referenced in the HP support document for the affected LoadRunner, Performance Center, and Monitor over Firewall agents.
  • Restrict network access to TCP port 54345 to trusted management hosts only, using firewall rules or network segmentation.
  • Disable or stop the vulnerable agent service on systems that do not require it.
  • Monitor vendor advisories for updated fixed versions and validate that deployed agents are patched.

Detection

  • Monitor network traffic to TCP port 54345 for unusually large or malformed server_ip_name fields or oversized packets.
  • Inspect host logs and process behavior for crashes or unexpected restarts of magentproc.exe.
  • Use IDS/IPS signatures targeting the mchan.dll overflow pattern if available.
  • Audit exposed services to identify any internet-facing or broadly reachable instances of the affected agent.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-0446 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-0446), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.