CVE-2007-0043
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer,"…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 30.7%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
The Just In Time (JIT) Compiler service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer," probably a buffer overflow, aka ".NET JIT Compiler Vulnerability".
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 30.67% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/.net framework
- Source
- secure@microsoft.com
References
- http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html
- http://osvdb.org/35956
- http://secunia.com/advisories/26003Vendor Advisory
- http://www.securityfocus.com/bid/24811
- http://www.securitytracker.com/id?1018356
- http://www.us-cert.gov/cas/techalerts/TA07-191A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2482Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34639
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1873
- http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html
- http://osvdb.org/35956
- http://secunia.com/advisories/26003Vendor Advisory
- http://www.securityfocus.com/bid/24811
- http://www.securitytracker.com/id?1018356
- http://www.us-cert.gov/cas/techalerts/TA07-191A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2482Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34639
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1873
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.