9.3

CVE-2007-0328

The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Macrovision ≫ Flexnet Connect Version 6.0
Macrovision ≫ Update Service Version 3.0
Macrovision ≫ Update Service Version 4.0
Macrovision ≫ Update Service Version 5.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.27% 0.915
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://support.installshield.com/kb/view.asp?articleid=Q113020
Patch
http://osvdb.org/36896
http://secunia.com/advisories/25501
Vendor Advisory
http://secunia.com/advisories/32842
Vendor Advisory
http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html
http://www.kb.cert.org/vuls/id/524681
Patch
US Government Resource
http://www.vupen.com/english/advisories/2007/2017
Vendor Advisory
http://www.vupen.com/english/advisories/2008/3278
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/34660