CVE-2007-0328: Critical severity Macrovision Update Service vulnerability
The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-0328?
CVE-2007-0328 is classified with a critical severity level due to its potential for remote command execution.
How do I fix CVE-2007-0328?
To mitigate CVE-2007-0328, users should update Macrovision FLEXnet Connect and Update Service to the latest versions available that address this vulnerability.
What software versions are affected by CVE-2007-0328?
CVE-2007-0328 affects Macrovision FLEXnet Connect version 6.0 and Macrovision Update Service versions 3.x to 5.x.
What is the nature of the vulnerability in CVE-2007-0328?
CVE-2007-0328 allows remote attackers to execute arbitrary commands through the Execute method of the DWUpdateService ActiveX control.
Can CVE-2007-0328 be exploited without authentication?
Yes, CVE-2007-0328 can be exploited by remote attackers without the need for authentication.