CVE-2008-4586 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 5.2% (pctl 92)
Patch early
A public exploit exists.
Description
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 5.17% — more likely to be exploited than 92% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2008-10-15 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| acresso | flexnet connect |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method | 2008-01-15 |
References
- http://secunia.com/advisories/28496
- http://securityreason.com/securityalert/4425
- http://www.securityfocus.com/bid/27279
- http://www.vupen.com/english/advisories/2008/0145
- https://www.exploit-db.com/exploits/4913
- http://secunia.com/advisories/28496
- http://securityreason.com/securityalert/4425
- http://www.securityfocus.com/bid/27279
- http://www.vupen.com/english/advisories/2008/0145
- https://www.exploit-db.com/exploits/4913
→ the Explorer · watch your stack · NVD