{"api_version":"1","generated_at":"2026-07-23T06:52:10+00:00","cve":"CVE-2007-0328","urls":{"html":"https://cve.report/CVE-2007-0328","api":"https://cve.report/api/cve/CVE-2007-0328.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0328","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0328"},"summary":{"title":"CVE-2007-0328","description":"The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.","state":"PUBLISHED","assigner":"certcc","published_at":"2007-06-01 00:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://secunia.com/advisories/25501","name":"http://secunia.com/advisories/25501","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Macrovision FLEXnet Connect DWUpdateService ActiveX Control Insecure Methods - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34660","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34660","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/524681","name":"http://www.kb.cert.org/vuls/id/524681","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","US Government Resource"],"title":"VU#524681 - Macrovision FLEXnet Connect Software Manager DWUpdateService ActiveX control contains dangerous methods","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2017","name":"http://www.vupen.com/english/advisories/2007/2017","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/32842","name":"http://secunia.com/advisories/32842","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"BlackBerry Desktop Software FlexNET Connect ActiveX Control Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html","name":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Updating an ActiveX control that the Roxio Media Manager uses","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/36896","name":"http://osvdb.org/36896","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020","name":"http://support.installshield.com/kb/view.asp?articleid=Q113020","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"View Document","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/3278","name":"http://www.vupen.com/english/advisories/2008/3278","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0328","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0328","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"328","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"flexnet_connect","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"328","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"328","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"4.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"328","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"update_service","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:12:18.093Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"36896","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/36896"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"32842","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/32842"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html"},{"name":"ADV-2007-2017","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2017"},{"name":"25501","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/25501"},{"name":"ADV-2008-3278","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/3278"},{"name":"VU#524681","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/524681"},{"name":"macrovision-dwupdate-command-execution(34660)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34660"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-05-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"36896","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/36896"},{"tags":["x_refsource_CONFIRM"],"url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"32842","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/32842"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html"},{"name":"ADV-2007-2017","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2017"},{"name":"25501","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/25501"},{"name":"ADV-2008-3278","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/3278"},{"name":"VU#524681","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/524681"},{"name":"macrovision-dwupdate-command-execution(34660)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34660"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-0328","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"36896","refsource":"OSVDB","url":"http://osvdb.org/36896"},{"name":"http://support.installshield.com/kb/view.asp?articleid=Q113020","refsource":"CONFIRM","url":"http://support.installshield.com/kb/view.asp?articleid=Q113020"},{"name":"32842","refsource":"SECUNIA","url":"http://secunia.com/advisories/32842"},{"name":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html","refsource":"CONFIRM","url":"http://www.blackberry.com/btsc/articles/749/KB16469_f.SAL_Public.html"},{"name":"ADV-2007-2017","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2017"},{"name":"25501","refsource":"SECUNIA","url":"http://secunia.com/advisories/25501"},{"name":"ADV-2008-3278","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/3278"},{"name":"VU#524681","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/524681"},{"name":"macrovision-dwupdate-command-execution(34660)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34660"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-0328","datePublished":"2007-06-01T00:00:00.000Z","dateReserved":"2007-01-17T00:00:00.000Z","dateUpdated":"2024-08-07T12:12:18.093Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-06-01 00:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:flexnet_connect:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2B07D756-3DB4-4ECD-83FD-CB60830F9267"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:3.0:*:*:*:*:*:*:*","matchCriteriaId":"A09B825D-2B5C-4BA8-AF5D-AB0C3FB61BA4"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:4.0:*:*:*:*:*:*:*","matchCriteriaId":"61E90832-465C-4C77-8171-36593FEF3DB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:update_service:5.0:*:*:*:*:*:*:*","matchCriteriaId":"8427D006-33CA-4677-9536-26596FB210D9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"328","Ordinal":"1","Title":"CVE-2007-0328","CVE":"CVE-2007-0328","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"328","Ordinal":"1","NoteData":"The DWUpdateService ActiveX control in the agent (agent.exe) in Macrovision FLEXnet Connect 6.0 and Update Service 3.x to 5.x allows remote attackers to execute arbitrary commands via (1) the Execute method, and obtain the exit status using (2) the GetExitCode method.","Type":"Description","Title":"CVE-2007-0328"},{"CveYear":"2007","CveId":"328","Ordinal":"2","NoteData":"2007-05-31","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"328","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}