Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
BID:31204
Info
Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
| Bugtraq ID: | 31204 |
| Class: | Origin Validation Error |
| CVE: |
CVE-2008-1093 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 16 2008 12:00AM |
| Updated: | Sep 16 2008 09:20PM |
| Credit: | Brian Dowling of Simplicity Communications |
| Vulnerable: |
Macrovision Update Service 6.0.100 60146 Macrovision Update Service 5.1.100 47363 Macrovision Update Service 6.1 Macrovision Update Service 5.0 Macrovision Update Service 4.0 Macrovision Update Service 3.0 InstallShield Software Corporation InstallShield Update Service 0 Acresso Software FLEXnet Connect 0 |
| Not Vulnerable: | |
Discussion
Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
Acresso FLEXnet Connect is prone to a remote code-execution vulnerability because it fails to adequately verify the authenticity of files obtained from update servers. The product has been formerly available as Macrovision FLEXnet Connect and as InstallShield Update Service.
Attackers can exploit this issue by performing man-in-the-middle attacks to have the client download and execute a malicious file hosted on an attacker-controlled computer. Other attacks may also be possible.
Acresso FLEXnet Connect is vulnerable. Additional products that use the FLEXnet functionality may also be vulnerable.
Acresso FLEXnet Connect is prone to a remote code-execution vulnerability because it fails to adequately verify the authenticity of files obtained from update servers. The product has been formerly available as Macrovision FLEXnet Connect and as InstallShield Update Service.
Attackers can exploit this issue by performing man-in-the-middle attacks to have the client download and execute a malicious file hosted on an attacker-controlled computer. Other attacks may also be possible.
Acresso FLEXnet Connect is vulnerable. Additional products that use the FLEXnet functionality may also be vulnerable.
Exploit / POC
Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
Attackers can exploit this issue by successfully performing a man-in-the-middle attack.
Attackers can exploit this issue by successfully performing a man-in-the-middle attack.
Solution / Fix
Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Acresso FLEXnet Connect 'GetRules.asp' Remote Code Execution Vulnerability
References:
References:
- FLEXnet Connect Homepage (Acresso Software)
- InstallShield Update Service Homepage (Acresso Software)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Vulnerability Note VU#837092 - InstallShield / Macrovision / Acresso FLEXnet Con (US-CERT)
- InstallShield Update Agent - Downloads and executes "Rule Scripts" insecurely. ("Brian Dowling"
)