The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0...
Vulnerability Description
The Macrovision InstallShield InstallScript One-Click Install (OCI) ActiveX control 12.0 before SP2 does not validate the DLL files that are named as parameters to the control, which allows remote attackers to download arbitrary library code onto a client machine.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-5661
Credits & Attribution
No credits recorded in the NVD database.
References
- http://securitytracker.com/id?1019735
- http://knowledge.macrovision.com/selfservice/microsites/search.do?cmd=displayKC&externalId=Q113640
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41558
- http://www.securityfocus.com/bid/28533
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=649
- http://secunia.com/advisories/29549
- http://www.vupen.com/english/advisories/2008/1049
Affected Vendor
revenera
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.