CVE-2007-5660
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 36.6%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 36.62% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- macrovision/flexnet connect · macrovision/installshield 2008 · macrovision/update service
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618
- http://osvdb.org/38347
- http://secunia.com/advisories/27475Patch, Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://support.installshield.com/kb/view.asp?articleid=Q113602Patch
- http://www.macrovision.com/promolanding/7660.htmPatch
- http://www.securityfocus.com/bid/26280Patch
- http://www.securitytracker.com/id?1018881
- http://www.vupen.com/english/advisories/2007/3670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38210
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618
- http://osvdb.org/38347
- http://secunia.com/advisories/27475Patch, Vendor Advisory
- http://support.installshield.com/kb/view.asp?articleid=Q113020Patch
- http://support.installshield.com/kb/view.asp?articleid=Q113602Patch
- http://www.macrovision.com/promolanding/7660.htmPatch
- http://www.securityfocus.com/bid/26280Patch
- http://www.securitytracker.com/id?1018881
- http://www.vupen.com/english/advisories/2007/3670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38210
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.