>> Macrovision InstallAnywhere Service Installation Password and Serial Bypass Weakness
Title : Macrovision InstallAnywhere Service Installation Password and Serial Bypass Weakness VUPEN ID : VUPEN/ADV-2007-1433 CVE ID : CVE-2007-1009
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-04-18
Technical Description
A weakness has been identified in Macrovision InstallAnywhere, which could be exploited by malicious users to bypass security checks. This issue is caused by an error within the serial number and password validation process, which could be exploited by malicious users to install an application without a valid password or serial number by manipulating the "InstallScript.iap_xml" XML project configuration file.
Subscribe to VUPEN VNS and receive real-time e-mail and SMS alerts when new advisories or patches relevant to your systems and network configurations are available.
Feedback If you have additional information or corrections for this security advisory please submit them via our contact form.