Vulnerability CVE-2007-1009


Published: 2007-04-19   Modified: 2012-02-12

Description:
Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Macrovision InstallAnywhere Password and Serial Number Bypass
Brian Reilly
23.04.2007

Type:

CWE-Other

CVSS2 => (AV:L/AC:L/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.6/10
6.4/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Macrovision -> Installanywhere 

 References:
http://securityreason.com/securityalert/2596
http://www.securityfocus.com/archive/1/466035/100/0/threaded
http://www.securityfocus.com/bid/22643
http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt
http://www.vupen.com/english/advisories/2007/1433

Copyright 2024, cxsecurity.com

 

Back to Top