Acresso InstallShield Update Agent does not properly verify the authenticity of Rule Scripts obtained from GetRules.asp web pages on FLEXnet Connect servers, which allows remote man-in-the-middle attackers to execute arbitrary VBScript code via Trojan horse Rules.
Software | From | Fixed in |
---|---|---|
acresso / flexnet_connect | - | - |
acresso / intallshield_update_agent | - | - |