Macrovision ActiveX control (isusweb.dll) code execution
| macrovision-isusweb-code-execution (38210) |
Description:
The Macrovision ActiveX control (isusweb.dll), which is included in the InstallShield Update Service, is vulnerable to arbitrary code execution, caused by insecure methods marked safe for scripting. By persuading a victim to visit a specially-crafted Web page, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or targeted application.
Platforms Affected:
- Macrovision, FLEXnet Connect 6.0
Remedy:
Refer to Macrovision Knowledge Base Article Q113020 and Q113602 for patch, upgrade, or suggested workaround information. See References.
Consequences:
Gain Access
References:
- iDefense PUBLIC ADVISORY: 10.31.07, Macrovision InstallShield Update Service ActiveX Unsafe Method Vulnerability at http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=618.
- Macrovision Knowledge Base Article Q113020, INFO: FLEXnet Connect 6.0 Security Patch at http://support.installshield.com/kb/view.asp?articleid=Q113020.
- Macrovision Knowledge Base Article Q113602, FLEXnet Connect 6.0 Security Patch at http://support.installshield.com/kb/view.asp?articleid=Q113602.
- Macrovision Web site, Important FLEXnet Connect Vulnerability Patch at http://www.macrovision.com/promolanding/7660.htm.
- BID-26280: Macrovision InstallShield Update Service Isusweb.DLL Multiple Remote Code Execution Vulnerabilities
- CVE-2007-5660: Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXnet Connect and InstallShield 2008 allows remote attackers to execute arbitrary code via an unspecified unsafe method
- FrSIRT/ADV-2007-3670: Macrovision Products Update Service ActiveX Multiple Insecure Methods
- SA27475: Macrovision Products Update Service ActiveX Control Insecure Methods
- SECTRACK ID: 1018881: Macrovision InstallShield Unsafe Method in Update Service ActiveX Control Lets Remote Users Execute Arbitrary Code
Reported:
Oct 30, 2007
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
