Lucene search

K
cveMitreCVE-2007-2419
HistoryJun 06, 2007 - 10:30 a.m.

CVE-2007-2419

2007-06-0610:30:00
mitre
web.nvd.nist.gov
32
cve-2007-2419
buffer overflow
activex control
macrovision flexnet connect
update service
remote code execution

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.115

Percentile

95.3%

Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.

Affected configurations

Nvd
Node
macrovisionflexnet_connectMatch6.0
OR
macrovisionupdate_serviceMatch3.0
OR
macrovisionupdate_serviceMatch4.0
OR
macrovisionupdate_serviceMatch5.0
VendorProductVersionCPE
macrovisionflexnet_connect6.0cpe:2.3:a:macrovision:flexnet_connect:6.0:*:*:*:*:*:*:*
macrovisionupdate_service3.0cpe:2.3:a:macrovision:update_service:3.0:*:*:*:*:*:*:*
macrovisionupdate_service4.0cpe:2.3:a:macrovision:update_service:4.0:*:*:*:*:*:*:*
macrovisionupdate_service5.0cpe:2.3:a:macrovision:update_service:5.0:*:*:*:*:*:*:*

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

7.6

Confidence

Low

EPSS

0.115

Percentile

95.3%