CVE-2007-5661: Code Injection
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2007-5661?
CVE-2007-5661 is considered critical due to its potential for remote code execution.
How do I fix CVE-2007-5661?
To mitigate CVE-2007-5661, upgrade the Macrovision InstallShield InstallScript to version 12.0 SP2 or later.
What systems are affected by CVE-2007-5661?
CVE-2007-5661 affects Macrovision InstallShield versions 12.0 up to service pack 1 for Premier and Professional editions.
What type of vulnerability is CVE-2007-5661?
CVE-2007-5661 is a remote code execution vulnerability that allows attackers to download and execute arbitrary code.
Who can exploit CVE-2007-5661?
Remote attackers can exploit CVE-2007-5661 if the vulnerable ActiveX control is implemented in client applications.