CVE-2007-6654: Buffer Overflow
Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2007-6654?
CVE-2007-6654 is classified as a critical vulnerability due to its potential for remote code execution.
What software is affected by CVE-2007-6654?
CVE-2007-6654 affects Macrovision InstallShield Update Service version 5.1.100.47363.
How do I fix CVE-2007-6654?
To remediate CVE-2007-6654, users should update to a patched version of the Macrovision InstallShield Update Service.
What kind of attack does CVE-2007-6654 enable?
CVE-2007-6654 enables remote attackers to execute arbitrary code on affected systems through a buffer overflow.
What is the exploit vector for CVE-2007-6654?
The exploit vector for CVE-2007-6654 involves sending a specially crafted long string in the ProductCode argument to the DownloadAndExecute method.