CVE-2016-4359: HP Loadrunner
Critical severity, CVSS 9.8. EPSS: 15.8% chance of exploitation in the next 30 days.
Stack-based buffer overflow in mchan.dll in the agent in HPE LoadRunner 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.02 through patch 2, and 12.50 through patch 3 and Performance Center 11.52 through patch 3, 12.00 through patch 1, 12.01 through patch 3, 12.20 through patch 2, and 12.50 through patch 1 allows remote attackers to execute arbitrary code via a long -server_name value, aka ZDI-CAN-3516.
Affected products
- HP Loadrunner: version 11.52 only; version 12.00 only; version 12.01 only; version 12.02 only; version 12.50 only
- HP Performance Center: version 11.52 only; version 12.00 only; version 12.01 only; version 12.20 only; version 12.50 only
Published 2016-06-08. Last modified 2026-06-17.