CVE-2007-2419: Buffer Overflow
Multiple buffer overflows in an ActiveX control (boisweb.dll) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allow remote attackers to execute arbitrary code via the (1) the second parameter to the DownloadAndExecute method and (2) third parameter to the AddFileEx method, a different vulnerability than CVE-2007-0328.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-2419?
CVE-2007-2419 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2007-2419?
To fix CVE-2007-2419, users should update to a patched version of Macrovision FLEXnet Connect or Update Service.
What systems are affected by CVE-2007-2419?
CVE-2007-2419 affects Macrovision FLEXnet Connect version 6.0 and Macrovision Update Service versions 3.x to 5.x.
What kind of attacks can exploit CVE-2007-2419?
CVE-2007-2419 can be exploited by remote attackers to execute arbitrary code through specially crafted parameters.
Is there a risk of data loss with CVE-2007-2419?
Yes, successful exploitation of CVE-2007-2419 can lead to data loss alongside unauthorized system access.