CVE-2007-5660 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 36.6% (pctl 98)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified "unsafe method," possibly involving a buffer overflow.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 36.62% — more likely to be exploited than 98% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-11-02 |
| Last modified | 2026-06-16 |
Affected (3)
| Vendor | Product |
|---|---|
| macrovision | flexnet connect |
| macrovision | installshield 2008 |
| macrovision | update service |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Macrovision Installshield Update Service - ActiveX Unsafe Method (Metasploit) | 2010-09-20 |
| exploit-db | Macrovision Installshield Update Service - Remote Buffer Overflow (Metasploit) | 2010-05-09 |
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618
- http://osvdb.org/38347
- http://secunia.com/advisories/27475
- http://support.installshield.com/kb/view.asp?articleid=Q113020
- http://support.installshield.com/kb/view.asp?articleid=Q113602
- http://www.macrovision.com/promolanding/7660.htm
- http://www.securityfocus.com/bid/26280
- http://www.securitytracker.com/id?1018881
- http://www.vupen.com/english/advisories/2007/3670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38210
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618
- http://osvdb.org/38347
- http://secunia.com/advisories/27475
- http://support.installshield.com/kb/view.asp?articleid=Q113020
- http://support.installshield.com/kb/view.asp?articleid=Q113602
- http://www.macrovision.com/promolanding/7660.htm
- http://www.securityfocus.com/bid/26280
- http://www.securitytracker.com/id?1018881
- http://www.vupen.com/english/advisories/2007/3670
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38210
→ the Explorer · watch your stack · NVD