Lucene search

K
cveCertccCVE-2007-0328
HistoryJun 01, 2007 - 12:30 a.m.

CVE-2007-0328

2007-06-0100:30:00
certcc
web.nvd.nist.gov
29
cve-2007-0328
dwupdateservice
activex control
remote code execution
arbitrary commands
security vulnerability

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.03

Percentile

91.1%

The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.

Affected configurations

Nvd
Node
macrovisionflexnet_connectMatch6.0
OR
macrovisionupdate_serviceMatch3.0
OR
macrovisionupdate_serviceMatch4.0
OR
macrovisionupdate_serviceMatch5.0
VendorProductVersionCPE
macrovisionflexnet_connect6.0cpe:2.3:a:macrovision:flexnet_connect:6.0:*:*:*:*:*:*:*
macrovisionupdate_service3.0cpe:2.3:a:macrovision:update_service:3.0:*:*:*:*:*:*:*
macrovisionupdate_service4.0cpe:2.3:a:macrovision:update_service:4.0:*:*:*:*:*:*:*
macrovisionupdate_service5.0cpe:2.3:a:macrovision:update_service:5.0:*:*:*:*:*:*:*

CVSS2

9.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

AI Score

7.5

Confidence

Low

EPSS

0.03

Percentile

91.1%

Related for CVE-2007-0328