{"api_version":"1","generated_at":"2026-07-23T05:22:45+00:00","cve":"CVE-2008-4586","urls":{"html":"https://cve.report/CVE-2008-4586","api":"https://cve.report/api/cve/CVE-2008-4586.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4586","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4586"},"summary":{"title":"CVE-2008-4586","description":"Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-15 22:45:31","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/27279","name":"http://www.securityfocus.com/bid/27279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Macrovision FLEXnet Connect ActiveX Control Multiple Arbitrary File Download Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2008/0145","name":"http://www.vupen.com/english/advisories/2008/0145","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28496","name":"http://secunia.com/advisories/28496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Macrovision FLEXnet Connect ActiveX Controls Insecure Methods - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4425","name":"http://securityreason.com/securityalert/4425","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4913","name":"https://www.exploit-db.com/exploits/4913","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4586","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4586","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4586","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"acresso","cpe5":"flexnet_connect","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:24:20.504Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"4913","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4913"},{"name":"4425","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4425"},{"name":"ADV-2008-0145","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28496"},{"name":"27279","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27279"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"4913","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4913"},{"name":"4425","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4425"},{"name":"ADV-2008-0145","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28496"},{"name":"27279","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27279"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4586","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"4913","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4913"},{"name":"4425","refsource":"SREASON","url":"http://securityreason.com/securityalert/4425"},{"name":"ADV-2008-0145","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","refsource":"SECUNIA","url":"http://secunia.com/advisories/28496"},{"name":"27279","refsource":"BID","url":"http://www.securityfocus.com/bid/27279"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4586","datePublished":"2008-10-15T22:00:00.000Z","dateReserved":"2008-10-15T00:00:00.000Z","dateUpdated":"2024-08-07T10:24:20.504Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-15 22:45:31","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:acresso:flexnet_connect:6.1:*:*:*:*:*:*:*","matchCriteriaId":"832ABFF7-1B6F-4ED8-A5C6-E53F580A0A58"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4586","Ordinal":"1","Title":"CVE-2008-4586","CVE":"CVE-2008-4586","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4586","Ordinal":"1","NoteData":"Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method.","Type":"Description","Title":"CVE-2008-4586"},{"CveYear":"2008","CveId":"4586","Ordinal":"2","NoteData":"2008-10-15","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4586","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}