VYPR
Unrated severityNVD Advisory· Published Apr 19, 2007· Updated Jun 16, 2026

CVE-2007-1009

CVE-2007-1009

Description

Macrovision InstallAnywhere Enterprise before 8.0.1 uses the InstallScript.iap_xml configuration file without integrity protection to verify authorization for installing an application, which allows local users to perform unauthorized installations by removing the (1) password or (2) serial number verification sections from this file.

Affected products

3
  • cpe:2.3:a:macrovision:installanywhere:8:*:enterprise:*:*:*:*:*+ 2 more
    • cpe:2.3:a:macrovision:installanywhere:8:*:enterprise:*:*:*:*:*
    • cpe:2.3:a:macrovision:installanywhere:8:*:standard:*:*:*:*:*
    • (no CPE)range: <8.0.1

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.