PT-2007-1799 · Macrovision · Macrovision Flexnet Connect+2

Will Dormann

·

Published

2007-06-01

·

Updated

2017-07-29

·

CVE-2007-0328

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Macrovision FLEXnet Connect versions 6.0 Macrovision FLEXnet Update Service versions 3.x through 5.x
Description: The issue allows remote attackers to execute arbitrary commands and obtain the exit status. This is achieved via the Execute method and the GetExitCode method.
Recommendations: For Macrovision FLEXnet Connect version 6.0, consider disabling the Execute method and GetExitCode method in the DWUpdateService ActiveX control until a patch is available. For Macrovision FLEXnet Update Service versions 3.x through 5.x, restrict access to the DWUpdateService ActiveX control to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0328

Affected Products

Dwupdateservice Activex Control
Macrovision Flexnet Connect
Macrovision Flexnet Update Service