Vulnerabilities > CVE-2008-4586 - Arbitrary File Download vulnerability in Acresso Flexnet Connect 6.1

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
acresso
critical
exploit available

Summary

Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macrovision FLEXnet Connect 6.1 allows remote attackers to force the download and execution of arbitrary files via the DownloadAndExecute method.

Vulnerable Configurations

Part Description Count
Application
Acresso
1

Exploit-Db

descriptionMacrovision FlexNet isusweb.dll DownloadAndExecute Method Exploit. CVE-2008-4586. Remote exploit for windows platform
fileexploits/windows/remote/4913.html
idEDB-ID:4913
last seen2016-01-31
modified2008-01-15
platformwindows
port
published2008-01-15
reporterElazar
sourcehttps://www.exploit-db.com/download/4913/
titleMacrovision FlexNet isusweb.dll DownloadAndExecute Method Exploit
typeremote