9.3

CVE-2007-0328

The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MacrovisionFlexnet Connect Version6.0
MacrovisionUpdate Service Version3.0
MacrovisionUpdate Service Version4.0
MacrovisionUpdate Service Version5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.27% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://support.installshield.com/kb/view.asp?articleid=Q113020
Patch
http://osvdb.org/36896
http://secunia.com/advisories/25501
Vendor Advisory
http://secunia.com/advisories/32842
Vendor Advisory
http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html
http://www.kb.cert.org/vuls/id/524681
Patch
US Government Resource
http://www.vupen.com/english/advisories/2007/2017
Vendor Advisory
http://www.vupen.com/english/advisories/2008/3278
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34660