{"api_version":"1","generated_at":"2026-07-23T06:06:50+00:00","cve":"CVE-2007-1009","urls":{"html":"https://cve.report/CVE-2007-1009","api":"https://cve.report/api/cve/CVE-2007-1009.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1009","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1009"},"summary":{"title":"CVE-2007-1009","description":"Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-04-19 10:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.6","severity":"","vector":"AV:L/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/22643","name":"http://www.securityfocus.com/bid/22643","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Macrovision InstallAnywhere Password Serial Number Authentication Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt","name":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"symantec.com has moved to broadcom.com","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://securityreason.com/securityalert/2596","name":"http://securityreason.com/securityalert/2596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision InstallAnywhere Password and Serial Number Bypass - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/1433","name":"http://www.vupen.com/english/advisories/2007/1433","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/466035/100/0/threaded","name":"http://www.securityfocus.com/archive/1/466035/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1009","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1009","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1009","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"installanywhere","cpe6":"8","cpe7":"*","cpe8":"enterprise","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"1009","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"macrovision","cpe5":"installanywhere","cpe6":"8","cpe7":"*","cpe8":"standard","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:43:21.662Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"2596","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2596"},{"name":"ADV-2007-1433","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/1433"},{"name":"20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/466035/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt"},{"name":"22643","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22643"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-04-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"2596","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2596"},{"name":"ADV-2007-1433","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/1433"},{"name":"20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/466035/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt"},{"name":"22643","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22643"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1009","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"2596","refsource":"SREASON","url":"http://securityreason.com/securityalert/2596"},{"name":"ADV-2007-1433","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/1433"},{"name":"20070416 SYMSA-2007-003 Macrovision InstallAnywhere Password and Serial Number Bypass","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/466035/100/0/threaded"},{"name":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt","refsource":"MISC","url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-003.txt"},{"name":"22643","refsource":"BID","url":"http://www.securityfocus.com/bid/22643"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1009","datePublished":"2007-04-19T10:00:00.000Z","dateReserved":"2007-02-20T00:00:00.000Z","dateUpdated":"2024-08-07T12:43:21.662Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-04-19 10:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","baseScore":4.6,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:installanywhere:8:*:enterprise:*:*:*:*:*","matchCriteriaId":"EF40B1C0-7A94-4C22-A73F-0601F9D6F6F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:macrovision:installanywhere:8:*:standard:*:*:*:*:*","matchCriteriaId":"74CCCC25-5CAE-4B44-9825-6E110F07BD68"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1009","Ordinal":"1","Title":"CVE-2007-1009","CVE":"CVE-2007-1009","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1009","Ordinal":"1","NoteData":"Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.","Type":"Description","Title":"CVE-2007-1009"},{"CveYear":"2007","CveId":"1009","Ordinal":"2","NoteData":"2007-04-19","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1009","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}