First published: Wed Oct 15 2008(Updated: )
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods. NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Macrovision FLEXnet Connect | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4587 has a high severity due to its potential for remote code execution.
To fix CVE-2008-4587, update the Macrovision FLEXnet Connect to a version that addresses this vulnerability.
CVE-2008-4587 exploits the AddFile and RunScheduledJobs methods of the ActiveX control.
Yes, there are known exploits that allow attackers to download and execute arbitrary files using this vulnerability.
CVE-2008-4587 primarily affects users of Macrovision FLEXnet Connect version 6.1.