4.6
CVE-2007-1009
- EPSS 0.32%
- Veröffentlicht 19.04.2007 10:19:00
- Zuletzt bearbeitet 16.06.2026 22:36:45
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Macrovision ≫ Installanywhere Version8 Editionenterprise
Macrovision ≫ Installanywhere Version8 Editionstandard
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.32% | 0.231 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
http://securityreason.com/securityalert/2596
http://www.securityfocus.com/archive/1/466035/100/0/threaded
http://www.securityfocus.com/bid/22643
http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt
http://www.vupen.com/english/advisories/2007/1433