PT-2007-1799 · Macrovision · Macrovision Flexnet Connect+2
Will Dormann
·
Published
2007-06-01
·
Updated
2017-07-29
·
CVE-2007-0328
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Macrovision FLEXnet Connect versions 6.0
Macrovision FLEXnet Update Service versions 3.x through 5.x
Description:
The issue allows remote attackers to execute arbitrary commands and obtain the exit status. This is achieved via the
Execute method and the GetExitCode method.Recommendations:
For Macrovision FLEXnet Connect version 6.0, consider disabling the
Execute method and GetExitCode method in the DWUpdateService ActiveX control until a patch is available.
For Macrovision FLEXnet Update Service versions 3.x through 5.x, restrict access to the DWUpdateService ActiveX control to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dwupdateservice Activex Control
Macrovision Flexnet Connect
Macrovision Flexnet Update Service