{"api_version":"1","generated_at":"2026-07-23T04:29:14+00:00","cve":"CVE-2008-4587","urls":{"html":"https://cve.report/CVE-2008-4587","api":"https://cve.report/api/cve/CVE-2008-4587.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2008-4587","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2008-4587"},"summary":{"title":"CVE-2008-4587","description":"Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods.  NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.","state":"PUBLISHED","assigner":"mitre","published_at":"2008-10-15 22:45:31","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.securityfocus.com/bid/27279","name":"http://www.securityfocus.com/bid/27279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision FLEXnet Connect ActiveX Control Multiple Arbitrary File Download Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39653","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39653","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/4428","name":"http://securityreason.com/securityalert/4428","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2008/0145","name":"http://www.vupen.com/english/advisories/2008/0145","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/28496","name":"http://secunia.com/advisories/28496","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Macrovision FLEXnet Connect ActiveX Controls Insecure Methods - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4909","name":"https://www.exploit-db.com/exploits/4909","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Macrovision FlexNet DownloadManager - Insecure Methods - Windows remote Exploit","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2008-4587","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2008-4587","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2008","cve_id":"4587","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"acresso","cpe5":"flexnet_connect","cpe6":"6.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T10:24:19.314Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2008-0145","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/28496"},{"name":"macrovision-flexnet-file-overwrite(39653)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39653"},{"name":"27279","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/27279"},{"name":"4909","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4909"},{"name":"4428","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/4428"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2008-01-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods.  NOTE: this could be leveraged for code execution by uploading executable files to Startup folders."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-09-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2008-0145","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/28496"},{"name":"macrovision-flexnet-file-overwrite(39653)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39653"},{"name":"27279","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/27279"},{"name":"4909","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4909"},{"name":"4428","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/4428"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2008-4587","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods.  NOTE: this could be leveraged for code execution by uploading executable files to Startup folders."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2008-0145","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2008/0145"},{"name":"28496","refsource":"SECUNIA","url":"http://secunia.com/advisories/28496"},{"name":"macrovision-flexnet-file-overwrite(39653)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/39653"},{"name":"27279","refsource":"BID","url":"http://www.securityfocus.com/bid/27279"},{"name":"4909","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4909"},{"name":"4428","refsource":"SREASON","url":"http://securityreason.com/securityalert/4428"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2008-4587","datePublished":"2008-10-15T22:00:00.000Z","dateReserved":"2008-10-15T00:00:00.000Z","dateUpdated":"2024-08-07T10:24:19.314Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2008-10-15 22:45:31","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:acresso:flexnet_connect:6.1:*:*:*:*:*:*:*","matchCriteriaId":"832ABFF7-1B6F-4ED8-A5C6-E53F580A0A58"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2008","CveId":"4587","Ordinal":"1","Title":"CVE-2008-4587","CVE":"CVE-2008-4587","Year":"2008"},"notes":[{"CveYear":"2008","CveId":"4587","Ordinal":"1","NoteData":"Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the AddFile and RunScheduledJobs methods.  NOTE: this could be leveraged for code execution by uploading executable files to Startup folders.","Type":"Description","Title":"CVE-2008-4587"},{"CveYear":"2008","CveId":"4587","Ordinal":"2","NoteData":"2008-10-15","Type":"Other","Title":"Published"},{"CveYear":"2008","CveId":"4587","Ordinal":"3","NoteData":"2017-09-28","Type":"Other","Title":"Modified"}]}}}