CVE-2008-4587
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.5%, higher than 95% of all known CVEs. Patch or mitigate before the next change window.
Description
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods. NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 10.51% probability · 95th percentile
- CISA KEV
- Not listed
- Affected
- acresso/flexnet connect
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/28496Vendor Advisory
- http://securityreason.com/securityalert/4428
- http://www.securityfocus.com/bid/27279
- http://www.vupen.com/english/advisories/2008/0145
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39653
- https://www.exploit-db.com/exploits/4909
- http://secunia.com/advisories/28496Vendor Advisory
- http://securityreason.com/securityalert/4428
- http://www.securityfocus.com/bid/27279
- http://www.vupen.com/english/advisories/2008/0145
- https://exchange.xforce.ibmcloud.com/vulnerabilities/39653
- https://www.exploit-db.com/exploits/4909
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.