Information disclosure in InstallShield - CVE-2007-6744

 

Information disclosure in InstallShield - CVE-2007-6744

Published: January 19, 2012 / Updated: August 11, 2020


Vulnerability identifier: #VU44374
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2007-6744
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
InstallShield
Software vendor:
Macrovision Corporation

Description

The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.

Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between InstallShield and Signcode.exe.


Remediation

Install update from vendor's website.

External links