CVE-2007-6654
Macrovision InstallShield Update Service Web Agent 5.1.100.47363 - Buffer Overflow via ProductCode
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-6654. PoCs published by Elazar.
AI-analyzed exploit summary This is a working proof-of-concept exploit for CVE-2007-6654, targeting a SEH overwrite vulnerability in Macrovision Installshield's isusweb.dll. It uses a heap spray technique to execute shellcode, demonstrating remote code execution via a malicious HTML file.
Description
Buffer overflow in a certain ActiveX control in Macrovision InstallShield Update Service Web Agent 5.1.100.47363 allows remote attackers to execute arbitrary code via a long string in the ProductCode argument (second argument) to the DownloadAndExecute method, a different vulnerability than CVE-2007-0321, CVE-2007-2419, and CVE-2007-5660.
Exploits (1)
This is a working proof-of-concept exploit for CVE-2007-6654, targeting a SEH overwrite vulnerability in Macrovision Installshield's isusweb.dll. It uses a heap spray technique to execute shellcode, demonstrating remote code execution via a malicious HTML file.