Overview
The Macrovision FLEXnet Connect Software Manager DWUpdateService ActiveX control fails to restrict access to its methods, which can allow a remote, unauthenticated attacker to execute arbitrary commands on a vulnerable system.
Description
Macrovision FLEXnet Connect is a software package that allows vendors to provide updates to applications. FLEXnet Connect-enabled software has the ability to
Note that this control may be provided by installing the FLEXnet Connect SDK, installing other InstallShield software, or also by running FLEXnet Connect-enabled Windows software. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page or an HTML email message or attachment), an attacker may be able to execute arbitrary commands with the privileges of the user. |
Solution
Apply an update |
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Will Dormann of CERT/CC.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2007-0328 |
Severity Metric: | 4.69 |
Date Public: | 2007-05-31 |
Date First Published: | 2007-05-31 |
Date Last Updated: | 2009-04-13 17:20 UTC |
Document Revision: | 16 |