CVE-2007-2419
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2)…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 5.53% probability · 92th percentile
- CISA KEV
- Not listed
- Affected
- macrovision/flexnet connect · macrovision/update service
- Source
- cve@mitre.org
References
- http://dvlabs.tippingpoint.com/advisory/TPTI-07-09Patch
- http://osvdb.org/36983
- http://secunia.com/advisories/25509Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://www.securityfocus.com/archive/1/470585/100/0/threaded
- http://www.securitytracker.com/id?1018195
- http://www.vupen.com/english/advisories/2007/2070
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34721
- http://dvlabs.tippingpoint.com/advisory/TPTI-07-09Patch
- http://osvdb.org/36983
- http://secunia.com/advisories/25509Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://www.securityfocus.com/archive/1/470585/100/0/threaded
- http://www.securitytracker.com/id?1018195
- http://www.vupen.com/english/advisories/2007/2070
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34721
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.