PT-2007-1799 · Macrovision · Macrovision Flexnet Connect+2
Will Dormann
·
Publicado
2007-06-01
·
Atualizado
2017-07-29
·
CVE-2007-0328
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Macrovision FLEXnet Connect versions 6.0
Macrovision FLEXnet Update Service versions 3.x through 5.x
Description:
The issue allows remote attackers to execute arbitrary commands and obtain the exit status. This is achieved via the
Execute method and the GetExitCode method.Recommendations:
For Macrovision FLEXnet Connect version 6.0, consider disabling the
Execute method and GetExitCode method in the DWUpdateService ActiveX control until a patch is available.
For Macrovision FLEXnet Update Service versions 3.x through 5.x, restrict access to the DWUpdateService ActiveX control to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Dwupdateservice Activex Control
Macrovision Flexnet Connect
Macrovision Flexnet Update Service