PT-2008-1509 · Macrovision · Installshield Installscript One-Click Install (Oci) Activex Control

Published

2008-04-04

·

Updated

2025-08-01

·

CVE-2007-5661

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control version 12.0 before SP2
Description The issue concerns the failure of the Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control to validate DLL files named as parameters, allowing remote attackers to download arbitrary library code onto a client machine.
Recommendations For Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control version 12.0 before SP2, apply Service Pack 2 to resolve the issue.

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2007-5661

Affected Products

Installshield Installscript One-Click Install (Oci) Activex Control