cbcvebase.
CVE-2016-4359
published 2016-06-08

CVE-2016-4359: Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through…

PriorityP263critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
15.77%
96.5th percentile
Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.

Affected

10 ranges
VendorProductVersion rangeFixed in
hploadrunner
hploadrunner
hploadrunner
hploadrunner
hploadrunner
hpperformance_center
hpperformance_center
hpperformance_center
hpperformance_center
hpperformance_center

Detection & IOCsextracted from sources · hover to see the quote

filenamemchan.dll
command-server_name
  • The vulnerability is triggered by a long -server_name value sent to the HPE LoadRunner/Performance Center agent (mchan.dll); monitor for oversized -server_name fields in agent communications.
  • CVE-2016-4359 is tracked internally as ZDI-CAN-3516 / ZDI-16-363 and maps to Tenable tracking TRA-13 / TRA-2016-16; use these identifiers when cross-referencing threat intel.
  • Tenable Nessus plugin loadrunner_agent_service_ip_name_overflow.nasl can be used to detect vulnerable LoadRunner agent instances.
  • ·Affected versions span multiple patch levels across LoadRunner and Performance Center; ensure patch level (not just major version) is checked when assessing exposure.

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.