The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:25
Type | Values Removed | Values Added |
---|---|---|
References | () http://osvdb.org/36896 - | |
References | () http://secunia.com/advisories/25501 - Vendor Advisory | |
References | () http://secunia.com/advisories/32842 - Vendor Advisory | |
References | () http://support.installshield.com/kb/view.asp?articleid=Q113020 - Patch | |
References | () http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html - | |
References | () http://www.kb.cert.org/vuls/id/524681 - Patch, US Government Resource | |
References | () http://www.vupen.com/english/advisories/2007/2017 - Vendor Advisory | |
References | () http://www.vupen.com/english/advisories/2008/3278 - Vendor Advisory | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/34660 - |
Information
Published : 2007-06-01 00:30
Updated : 2024-11-21 00:25
NVD link : CVE-2007-0328
Mitre link : CVE-2007-0328
CVE.ORG link : CVE-2007-0328
JSON object : View
Products Affected
macrovision
- flexnet_connect
- update_service
CWE