CVE-2007-0328
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.27%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 5.27% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- macrovision/flexnet connect · macrovision/update service
- Source
- cret@cert.org
References
- http://osvdb.org/36896
- http://secunia.com/advisories/25501Vendor Advisory
- http://secunia.com/advisories/32842Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html
- http://www.kb.cert.org/vuls/id/524681Patch, US Government Resource
- http://www.vupen.com/english/advisories/2007/2017Vendor Advisory
- http://www.vupen.com/english/advisories/2008/3278Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34660
- http://osvdb.org/36896
- http://secunia.com/advisories/25501Vendor Advisory
- http://secunia.com/advisories/32842Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html
- http://www.kb.cert.org/vuls/id/524681Patch, US Government Resource
- http://www.vupen.com/english/advisories/2007/2017Vendor Advisory
- http://www.vupen.com/english/advisories/2008/3278Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34660
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.