4.6
CVSSv2

CVE-2007-1009

Published: 19/04/2007 Updated: 16/10/2018
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 409
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Macrovision InstallAnywhere Enterprise prior to 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.

Vulnerable Product Search on Vulmon Subscribe to Product

macrovision installanywhere 8