CVE-2008-4587: Critical severity macrovision flexnet connect vulnerability
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods. NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-4587?
CVE-2008-4587 has a high severity due to its potential for remote code execution.
How do I fix CVE-2008-4587?
To fix CVE-2008-4587, update the Macrovision FLEXnet Connect to a version that addresses this vulnerability.
What methods are exploited in CVE-2008-4587?
CVE-2008-4587 exploits the AddFile and RunScheduledJobs methods of the ActiveX control.
Are there known exploits for CVE-2008-4587?
Yes, there are known exploits that allow attackers to download and execute arbitrary files using this vulnerability.
Who is affected by CVE-2008-4587?
CVE-2008-4587 primarily affects users of Macrovision FLEXnet Connect version 6.1.