<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://msmvps.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>InstallSite Blog : FLEXnet Connect</title><link>http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx</link><description>Tags: FLEXnet Connect</description><dc:language>en</dc:language><generator>CommunityServer 2008.5 SP2 (Build: 40407.4157)</generator><item><title>FLEXnet Connect 6.1 Security Update</title><link>http://msmvps.com/blogs/installsite/archive/2009/02/16/flexnet-connect-6-1-security-update.aspx</link><pubDate>Mon, 16 Feb 2009 10:43:44 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1672583</guid><dc:creator>stefan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1672583</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2009/02/16/flexnet-connect-6-1-security-update.aspx#comments</comments><description>&lt;p&gt;Acresso has published a fix for a security issue in FLEXnet Connect (previously called InstallShield Update Service) that was &lt;a href="http://msmvps.com/blogs/installsite/archive/2008/09/18/security-vulnerability-in-flexnet-connect-installshield-update-service.aspx"&gt;reported&lt;/a&gt; in September 2008.&lt;/p&gt;  &lt;p&gt;The problem was that FLEXnet connect used an unauthenticated HTTP connection to download and execute scripts from the update server. Therefore an attacker could cause the client to execute malicious scripts, for instance by redirecting the connection using a proxy or a DNS attack.&lt;/p&gt;  &lt;p&gt;The update is only available for FLEXnet Connect version 6.1. According to the &lt;a href="http://www.kb.cert.org/vuls/id/837092" target="_blank"&gt;US-CERT&lt;/a&gt; FLEXnet Connect version 11.1.100.17104 or higher is not affected by the problem.&lt;/p&gt;  &lt;p&gt;&lt;a href="http://kb.acresso.com/selfservice/documentLink.do?externalID=Q200637" target="_blank"&gt;Acresso’s knowledge base article&lt;/a&gt; about the security update has no technical details about how the problem was fixed.&lt;/p&gt;  &lt;p&gt;The update is available for the FLEXnet Connect client agent which is already installed on end users’ computers and for the FLEXnet Connect SDK which developers adding FLEXnet Connect to their setup should install on their development machines.&lt;/p&gt;  &lt;p&gt;To deploy the end user hotfix to your customers, create and publish an update to your product, as described in the knowledge base article.&lt;/p&gt;  &lt;p&gt;To install the fixed SDK, you must first manually uninstall the previous version from your development machine (I wonder why Acresso isn’t using a Major Upgrade for this purpose).&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1672583" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Acresso/default.aspx">Acresso</category></item><item><title>Security Vulnerability in FLEXnet Connect / InstallShield Update Service</title><link>http://msmvps.com/blogs/installsite/archive/2008/09/18/security-vulnerability-in-flexnet-connect-installshield-update-service.aspx</link><pubDate>Thu, 18 Sep 2008 07:10:40 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1648163</guid><dc:creator>stefan</dc:creator><slash:comments>2</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1648163</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2008/09/18/security-vulnerability-in-flexnet-connect-installshield-update-service.aspx#comments</comments><description>&lt;p&gt;When checking for updates, the FLEXnet Connect client (and it&amp;#39;s previous versions named InstallShield Update Service) can download and execute scripts from the update server. The problem is that these scripts are downloaded via HTTP, so the identity of the server isn&amp;#39;t verified and the scripts are not encrypted. Therefore an attacker could cause the client to execute malicious scripts, for instance by redirecting the connection using a proxy or a DNS attack. There&amp;#39;s no fix available but the following article from the US-CERT (United States Computer Emergency Readiness Team) lists some possible workarounds:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://www.kb.cert.org/vuls/id/837092" target="_blank"&gt;Vulnerability Note VU#837092: InstallShield / Macrovision / Acresso FLEXnet Connect insecurely retrieves and executes scripts&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1648163" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Acresso/default.aspx">Acresso</category></item><item><title>InstallShield 2009 Upgrade Caveats</title><link>http://msmvps.com/blogs/installsite/archive/2008/06/14/installshield-2009-upgrade-caveats.aspx</link><pubDate>Sat, 14 Jun 2008 10:07:20 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1634954</guid><dc:creator>stefan</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1634954</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2008/06/14/installshield-2009-upgrade-caveats.aspx#comments</comments><description>&lt;p&gt;There are many great new features, improvements and bug fixes in InstallShield 2009, as detailed in the &lt;a href="http://kb.acresso.com/selfservice/microsites/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=Q200150" target="_blank"&gt;release notes&lt;/a&gt;. But if you consider upgrading to the new version you also should be aware of some changes that might be a problem for your projects. I&amp;#39;d like to highlight the following issues, but please also review &lt;a href="http://kb.acresso.com/selfservice/microsites/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=Q200151&amp;amp;sliceId=" target="_blank"&gt;knowledge base article Q200151&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;Stand Alone Build engine&lt;/strong&gt; (SAB) is only available for owners of the Premier edition. It was removed from the Professional edition with the release of InstallShield 12, but users upgrading from InstallShield Professional 10.x or 11.x which included the SAB could get the current version free of charge. With InstallShield 2009 this is no longer possible. If you need the Stand Alone Build you must buy Premier.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;FLEXnet Connect&lt;/strong&gt; (formerly InstallShield Update Service) support is only available in MSI projects. If you are using pure InstallScript projects you can no longer add this update notification tool to your setup. For InstallScript MSI it is still available but some script functions related to FLEXnet Connect have been removed. For Basic MSI projects FLEXnet Connect continues to be supported as usual. (FLEXnet Connect is an add-on to InstallShield that is charged separately.)&lt;/p&gt; &lt;p&gt;For more information:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://kb.acresso.com/selfservice/microsites/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=Q200151&amp;amp;sliceId=" target="_blank"&gt;Q200151: Upgrading Projects to InstallShield 2009&lt;/a&gt;  &lt;li&gt;&lt;a href="http://www.acresso.com/webdocuments/PDF/eula_IS2009_en.pdf" target="_blank"&gt;InstallShield 2009 EULA&lt;/a&gt; (PDF)  &lt;li&gt;&lt;a href="http://kb.acresso.com/selfservice/microsites/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=Q200150" target="_blank"&gt;Q200150: InstallShield 2009 Release Notes&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1634954" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Acresso/default.aspx">Acresso</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/InstallShield/default.aspx">InstallShield</category></item><item><title>New Security Vulnerability in FLEXnet Connect</title><link>http://msmvps.com/blogs/installsite/archive/2008/01/20/new-security-vulnerability-in-flexnet-connect.aspx</link><pubDate>Sun, 20 Jan 2008 12:23:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1471784</guid><dc:creator>stefan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1471784</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2008/01/20/new-security-vulnerability-in-flexnet-connect.aspx#comments</comments><description>&lt;p&gt;New reports about security vulnerabilities in Macrovision&amp;#39;s FLEXnet Connect (formerly called InstallShield Update Service) have been published on January 15, &lt;strike&gt;2007&lt;/strike&gt; 2008. The vulnerability would enable an attacker to remotely run malicious code on a users machine. The following files are affected:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;isusweb.dll version 6.1.100.61372&lt;/li&gt;
&lt;li&gt;ISDM.exe version 6.1.100.61372&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;Other versions may also be affected. 
&lt;p&gt;Sample exploit code is available on the web. 
&lt;p&gt;Macrovision has not yet replied to my request for a confirmation of these reports. As a workaround you should set the kill bit for the affected ActiveX controls (see below articles for details). 
&lt;p&gt;Setups created with Macrovision&amp;#39;s InstallShield often ship the FLEXnet Connect/Update Service client by default, even if the author isn&amp;#39;t actually using it. I recommend that you review your setup packages and inform your customers, if your setup installed the vulnerable files on their machines.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="http://secunia.com/advisories/28496/" target="_blank"&gt;Secunia Advisory SA28496&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://secwatch.org/advisories/1020062/" target="_blank"&gt;Secwatch.org Advisory SWID1020062&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="http://www.securityfocus.com/bid/27279/" target="_blank"&gt;SecurityFocus Bugtraq ID 27279&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;
&lt;p&gt;[edit 2008-02-25: corrected the date]&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1471784" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Web+Resources/default.aspx">Web Resources</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>More on the security patch for FLEXnet Connect</title><link>http://msmvps.com/blogs/installsite/archive/2007/11/02/more-on-the-security-patch-for-flexnet-connect.aspx</link><pubDate>Fri, 02 Nov 2007 11:18:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1278199</guid><dc:creator>stefan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1278199</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/11/02/more-on-the-security-patch-for-flexnet-connect.aspx#comments</comments><description>&lt;p&gt;Some additional information about the &lt;a href="http://msmvps.com/blogs/installsite/archive/2007/10/30/security-patch-for-flexnet-connect.aspx" target="_blank"&gt;recently reported&lt;/a&gt; security vulnerability in FLEXnet Connect:&lt;/p&gt;
&lt;p&gt;According to &lt;a href="http://secunia.com/advisories/27475/" target="_blank"&gt;Secunia&lt;/a&gt; the vulnerability is reported in versions 5.01.100.47363 and 6.0.100.60146 of the Update Service ActiveX control (isusweb.dll), but other versions may also be affected. It is recommended that you update all machines which have versions prior to 6.0.100.65101 installed, or set the kill bit for the affected control. For more information see the advisory from &lt;a href="http://www.verisign.com/security-intelligence-service/current-intelligence/vulnerability-advisories/2007/618.html" target="_blank"&gt;VeriSign iDefense Security Intelligence Service&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;A stand-alone installer to update the FLEXnet Connect Client on your end users&amp;#39; machines is available (&lt;a href="http://saturn.installshield.com/isus/600/update/setup.exe" target="_blank"&gt;Download&lt;/a&gt;). Unfortunately the installer isn&amp;#39;t digitally signed, so it will display a UAC dialog with yellow title bar on Windows Vista, warning about an unidentified program. Note that this stand-alone installer will not update the redistributables on your development machine. You need to install the latest Connect SDK to do this.&lt;/p&gt;
&lt;p&gt;To update the files in the InstallShield Redist folders on your development machine, &lt;a href="http://saturn.installshield.com/isus/600/windowssdk/flexnetconnectsdk.exe" target="_blank"&gt;download&lt;/a&gt; and install the latest version of the FLEXnet Connect SDK. I did this on a machine which has both InstallShield 12 and InstallShield 2008 installed. This updated the files in the Macrovision\IS12\Redist\Update Service folder, but not in its IS2008 counterpart. So after installing the SDK you should verify the version numbers and update the files manually as needed.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1278199" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Web+Resources/default.aspx">Web Resources</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Security patch for FLEXnet Connect</title><link>http://msmvps.com/blogs/installsite/archive/2007/10/30/security-patch-for-flexnet-connect.aspx</link><pubDate>Tue, 30 Oct 2007 17:00:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:1274624</guid><dc:creator>stefan</dc:creator><slash:comments>1</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=1274624</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/10/30/security-patch-for-flexnet-connect.aspx#comments</comments><description>&lt;p&gt;Today, Macrovision Corp. notified customers of FLEXnet Connect® (formerly called InstallShield Update Service) of a security vulnerability in the FLEXnet Connect client version 6.0. Customers using the FLEXnet Connect functionality that is bundled with some editions of InstallShield and AdminStudio are also affected. The problem only exists in the Windows client, not the Universal client. Also, version 6.1 is not affected.&lt;/p&gt; &lt;p&gt;Macrovision has released a patch to fix the vulnerability. If you are using FLEXnet connect and distributed the client to your customers, you need to take action as soon as possible. After updating the Connect SDK on your development machine you have to create an update for your application setup and ship it to your customers in order to update the Connect client on their machines. &lt;/p&gt; &lt;p&gt;Macrovision knowledge base articles:&lt;/p&gt; &lt;ul&gt; &lt;li&gt;&lt;a href="http://support.installshield.com/kb/view.asp?articleid=Q113020" target="_blank"&gt;Q113020&lt;/a&gt;  &lt;li&gt;&lt;a href="http://support.installshield.com/kb/view.asp?articleid=Q113602" target="_blank"&gt;Q113602&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt; &lt;p&gt;Side note: End users can&amp;#39;t update the client dircetly from Macrovision because it was installed by your setup as a merge module. This servicing limitation is making merge modules less popular these days, see Rule 43 in the &lt;a href="http://blogs.msdn.com/windows_installer_team/archive/2006/06/27/648447.aspx" target="_blank"&gt;Tao of the Windows Installer&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=1274624" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Web+Resources/default.aspx">Web Resources</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Macrovision preparing end-user patch for FLEXnet Connect/Update Service security issues</title><link>http://msmvps.com/blogs/installsite/archive/2007/06/21/macrovision-preparing-end-user-patch-for-flexnet-connect-update-service-security-issues.aspx</link><pubDate>Thu, 21 Jun 2007 19:32:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:978820</guid><dc:creator>stefan</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=978820</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/06/21/macrovision-preparing-end-user-patch-for-flexnet-connect-update-service-security-issues.aspx#comments</comments><description>&lt;p&gt;Updated information about the recent security vulnerability reports in Macrovision&amp;#39;s FLEXnet Connect and InstallShield Update Service products: Product manager Trent Wheeler told me they are currently in the process of rolling out the fix for the two problems reported by US-CERT&amp;nbsp;to customers of InstallShield, AdminStudio, and other Macrovision products that utilize the FLEXnet Connect product.&amp;nbsp; &lt;/p&gt;
&lt;p&gt;And they are writing an additional patch, one that is appropriate for end-users of FLEXnet Connect to apply directly to the installed version of the agent rather than the intermediate consumers of&amp;nbsp;the SDK.&amp;nbsp;This will be made generally available to customers of Macrovision&amp;#39;s products that utilize FLEXnet Connect, and to interested 3rd parties, as soon as it clears QA.&lt;/p&gt;
&lt;p&gt;Related articles:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://msmvps.com/blogs/installsite/archive/2007/06/01/937413.aspx" target="_blank"&gt;Security vulnerability in FLEXnet Connect/InstallShield Update Service end user ActiveX control (reported May 31, 2007)&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://msmvps.com/blogs/installsite/archive/2007/06/02/938694.aspx" target="_blank"&gt;Update on the FLEXnet Connect/InstallShield Update Service vulnerability&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;
&lt;li&gt;
&lt;div&gt;&lt;a class="" href="http://msmvps.com/blogs/installsite/archive/2007/06/06/945993.aspx" target="_blank"&gt;Doubts about yet another FLEXnet Connect/InstallShield Update Service vulnerability report&lt;/a&gt;&lt;/div&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=978820" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Doubts about yet another FLEXnet Connect/InstallShield Update Service vulnerability report</title><link>http://msmvps.com/blogs/installsite/archive/2007/06/06/doubts-about-yet-another-flexnet-connect-installshield-update-service-vulnerability-report.aspx</link><pubDate>Wed, 06 Jun 2007 09:58:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:945993</guid><dc:creator>stefan</dc:creator><slash:comments>6</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=945993</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/06/06/doubts-about-yet-another-flexnet-connect-installshield-update-service-vulnerability-report.aspx#comments</comments><description>&lt;p&gt;On June 4th TippingPoint, a provider of network-based intrusion prevention systems, reported a new buffer overflow vulnerability that affects Macrovision FLEXnet Connect version 6 and InstallShield Update Service versions 3-5.&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://dvlabs.tippingpoint.com/advisory/TPTI-07-09" target="_blank"&gt;TippingPoint Vulnerability Report&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;What puzzles me is the CLSID of the vulnerable ActiveX control: 85A4A99C-8C3D-499E-A386-E0743DFF8FB7. I&amp;nbsp;couldn&amp;#39;t find this&amp;nbsp;CLSID in my registry. But instead I found reports which associate this CLSID with a vulnerable Yahoo Mesenger ActiveX control: &lt;a class="" href="http://www.kb.cert.org/vuls/id/388377" target="_blank"&gt;US-CERT Vulnerability Note VU#388377&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;According to the TippingPoint review the vulnerable ActiveX control is in the file boisweb.dll. I don&amp;#39;t have this file on my computer either, and I&amp;#39;ve never seen such a file. Searching the web for this file name found many copies and quotes of this vulnerability report, but nothing else.&lt;/p&gt;
&lt;p&gt;This really makes me wonder how reliable this report from TippingPoint is. But they say&amp;nbsp;you should be safe if you install the latest version of the FLEXnet Connect SDK which you should do anyway to address the &lt;a class="" href="http://msmvps.com/blogs/installsite/archive/2007/06/02/938694.aspx" target="_blank"&gt;other vulnerability&lt;/a&gt;.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=945993" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Update on the FLEXnet Connect/InstallShield Update Service vulnerability</title><link>http://msmvps.com/blogs/installsite/archive/2007/06/02/update-on-the-flexnet-connect-installshield-update-service-vulnerability.aspx</link><pubDate>Sat, 02 Jun 2007 12:46:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:938694</guid><dc:creator>stefan</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=938694</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/06/02/update-on-the-flexnet-connect-installshield-update-service-vulnerability.aspx#comments</comments><description>&lt;p&gt;While doing some research on the &lt;a class="" href="http://msmvps.com/blogs/installsite/archive/2007/06/01/937413.aspx" target="_blank"&gt;security vulnerability in&amp;nbsp;FLEXnet Connect and InstallShield Update Service&lt;/a&gt;&amp;nbsp;I checked several versions of the agent.exe redistributable and it seems that it&amp;#39;s using different CLSIDs in each release. The &lt;a class="" href="http://www.kb.cert.org/vuls/id/524681" target="_blank"&gt;US-CERT advisory&lt;/a&gt; recommends setting the kill-bit for the control.&amp;nbsp;But since its CLSID keeps changing this is quite difficult. The CLSID listed in the US-CERT article appears to apply only to the latest (= fixed) version. So (unless I&amp;#39;m mistaken, which is quite possible) the kill-bit workaround from US-CERT will NOT work and you are still vulnerable.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=938694" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Security vulnerability in FLEXnet Connect/InstallShield Update Service end user ActiveX control (reported May 31, 2007)</title><link>http://msmvps.com/blogs/installsite/archive/2007/06/01/security-vulnerability-in-flexnet-connect-installshield-update-service-end-user-activex-control-reported-may-31-2007.aspx</link><pubDate>Fri, 01 Jun 2007 12:53:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:937413</guid><dc:creator>stefan</dc:creator><slash:comments>4</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=937413</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/06/01/security-vulnerability-in-flexnet-connect-installshield-update-service-end-user-activex-control-reported-may-31-2007.aspx#comments</comments><description>&lt;p&gt;The United States Computer Emergency Readiness Team (US-CERT) reports a newly found security vulnerability in Macrovision&amp;#39;s FLEXnet Connect. It also affects end user machines where the update agent has been installed, which many setups created with&amp;nbsp;InstallShield do by default. &lt;/p&gt;
&lt;p&gt;FLEXnet Connect includes an ActiveX control called DWUpdateService, which is provided by the file agent.exe. This ActiveX control fails to restrict access to its methods, which can allow a remote, unauthenticated attacker to execute arbitrary commands on a vulnerable system.&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://www.kb.cert.org/vuls/id/524681" target="_blank"&gt;US-CERT Vulnerability Note VU#524681&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Reportedly the vulnerability affects FLEXnet Connect 6.0 and InstallShield Update Service 3.x to 5.x. Macrovision released an update for this file, which had previously been affected by another vulnerability (&lt;a class="" href="http://www.kb.cert.org/vuls/id/847993" target="_blank"&gt;US-CERT VU#847993&lt;/a&gt;):&lt;/p&gt;
&lt;p&gt;&lt;a class="" href="http://support.installshield.com/kb/view.asp?articleid=Q113020" target="_blank"&gt;FLEXnet Connect 6.0 Security Patch&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;If you are using the affected products, you should install the update and also &lt;strong&gt;deploy it to your customer base&lt;/strong&gt; as soon as possible.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=937413" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item><item><title>Security Vulnerabilities in InstallShield Runtime Files on End User Machines</title><link>http://msmvps.com/blogs/installsite/archive/2007/03/05/security-vulnerabilities-in-installshield-runtime-files-on-end-user-machines.aspx</link><pubDate>Mon, 05 Mar 2007 17:55:00 GMT</pubDate><guid isPermaLink="false">d67277c4-116b-43f1-b688-e9ef184ea916:644153</guid><dc:creator>stefan</dc:creator><slash:comments>0</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://msmvps.com/blogs/installsite/rsscomments.aspx?PostID=644153</wfw:commentRss><comments>http://msmvps.com/blogs/installsite/archive/2007/03/05/security-vulnerabilities-in-installshield-runtime-files-on-end-user-machines.aspx#comments</comments><description>&lt;p&gt;The United States Computer Emergency Readiness Team (US-CERT) reported critical security vulnerabilities in two ActiveX controls and a Netscape plug-in that InstallShield/Macrovision products install on end user machines. According to the reports the vulnerabilities can be exploited execute arbitrary code if the victim views a specially crafted HTML document, e.g. a web page or an HTML e-mail.&lt;/p&gt;
&lt;p&gt;The affected products are:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;FLEXnet Connect / InstallShield Update Service&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The InstallShield Update Service Web Agent ActiveX control contains a buffer overflow, which could allow an attacker to execute arbitrary code on a vulnerable system. InstallShield Update Service is now called FLEXnet Connect.&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a class="" href="http://www.kb.cert.org/vuls/id/847993" target="_blank"&gt;US-CERT Report&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Macrovision has released a patch to solve this problem based on version 6.0 of the FLEXnet Connect Windows agent. This does not affect the Java agent. It is recommended that you deploy this patch as soon as possible to your customer base. An e-mail with instructions has been sent to FLEXnet Connect customers.&lt;br /&gt;Alternatively you can set the kill bit for the affected ActiveX control as described in the US-CERT report.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;InstallFromTheWeb (IFTW)&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The InstallShield InstallFromTheWeb ActiveX control and Netscape plug-in both contain multiple buffer overflows, which could allow an attacker to execute arbitrary code on a vulnerable system. &lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;a class="" href="http://www.kb.cert.org/vuls/id/181041" target="_blank"&gt;US-CERT Report&lt;/a&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;Macrovision sent me the following reply when I asked them for a comment on the&amp;nbsp;IFTW vulnerability:&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;&lt;em&gt;Regarding InstallFromTheWeb, our position is that InstallFromTheWeb is an obsolete product from Macrovision.&amp;nbsp; This product has already passed it&amp;#39;s end-of-life period, therefore Macrovision is no longer supporting this product.&lt;br /&gt;We recommend, where it makes sense, that all IFTW customers use the current version of InstallShield, InstallShield 12, instead of InstallFromTheWeb.&amp;nbsp; InstallShield 12 does not have the vulnerability issue.&lt;/em&gt;&lt;/p&gt;&lt;/blockquote&gt;
&lt;p&gt;InstallFromTheWeb was sold as a product from 1997 through early 2000, when it was replaced by One-Click Installs (OCI) in InstallShield Professional 6.2.&lt;/p&gt;
&lt;p&gt;The&amp;nbsp;workaround for the IFTW vulnerability is setting the kill bit for the affected ActiveX control, or deleting the Netscape plug-in, respectively, as described in the US-CERT report.&lt;/p&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://msmvps.com/aggbug.aspx?PostID=644153" width="1" height="1"&gt;</description><category domain="http://msmvps.com/blogs/installsite/archive/tags/Industry+News/default.aspx">Industry News</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Security/default.aspx">Security</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/Macrovision/default.aspx">Macrovision</category><category domain="http://msmvps.com/blogs/installsite/archive/tags/FLEXnet+Connect/default.aspx">FLEXnet Connect</category></item></channel></rss>