CVE-2007-5660
Macrovision Installshield Update Service - ActiveX Unsafe Method
Severity Score
9.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
Vulnerabilidad sin especificar en el control de ActiveX Update Service en el isusweb.dll anterior al 6.0.100.65101 en el MacroVision FLEXnet Connect y InstallShield 2008 permite a atacantes remotos ejecutar código de su elección a través de "un método inseguro" sin especificar y, posiblemente, involucrando un desbordamiento de búfer.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2007-10-23 CVE Reserved
- 2007-10-31 CVE Published
- 2010-05-09 First Exploit
- 2024-08-07 CVE Updated
- 2024-09-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
CAPEC
References (12)
URL | Tag | Source |
---|---|---|
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618 | Third Party Advisory | |
http://osvdb.org/38347 | Vdb Entry | |
http://www.securitytracker.com/id?1018881 | Vdb Entry | |
http://www.vupen.com/english/advisories/2007/3670 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/38210 | Vdb Entry |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/16602 | 2010-09-20 | |
https://www.exploit-db.com/exploits/16573 | 2010-05-09 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/27475 | 2017-07-29 | |
http://support.installshield.com/kb/view.asp?articleid=Q113020 | 2017-07-29 | |
http://support.installshield.com/kb/view.asp?articleid=Q113602 | 2017-07-29 | |
http://www.macrovision.com/promolanding/7660.htm | 2017-07-29 | |
http://www.securityfocus.com/bid/26280 | 2017-07-29 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Macrovision Search vendor "Macrovision" | Flexnet Connect Search vendor "Macrovision" for product "Flexnet Connect" | * | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Installshield 2008 Search vendor "Macrovision" for product "Installshield 2008" | * | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Update Service Search vendor "Macrovision" for product "Update Service" | 3.0 Search vendor "Macrovision" for product "Update Service" and version "3.0" | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Update Service Search vendor "Macrovision" for product "Update Service" | 4.0 Search vendor "Macrovision" for product "Update Service" and version "4.0" | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Update Service Search vendor "Macrovision" for product "Update Service" | 5.0 Search vendor "Macrovision" for product "Update Service" and version "5.0" | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Update Service Search vendor "Macrovision" for product "Update Service" | 5.1.100_47363 Search vendor "Macrovision" for product "Update Service" and version "5.1.100_47363" | - |
Affected
| ||||||
Macrovision Search vendor "Macrovision" | Update Service Search vendor "Macrovision" for product "Update Service" | 6.0.100_60146 Search vendor "Macrovision" for product "Update Service" and version "6.0.100_60146" | - |
Affected
|