CVE-2007-0515
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 38.4%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Unspecified vulnerability in Microsoft Word allows user-assisted remote attackers to execute arbitrary code on Word 2000, and cause a denial of service on Word 2003, via unknown attack vectors that trigger memory corruption, as exploited by Trojan.Mdropper.W and later by Trojan.Mdropper.X, a different issue than CVE-2006-6456, CVE-2006-5994, and CVE-2006-6561.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 38.39% probability · 98th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/office · microsoft/word · microsoft/word viewer · microsoft/works
- Source
- cve@mitre.org
References
- http://isc.sans.org/diary.html?storyid=2133
- http://osvdb.org/31900
- http://secunia.com/advisories/23950Vendor Advisory
- http://securitytracker.com/id?1017564
- http://www.kb.cert.org/vuls/id/412225US Government Resource
- http://www.microsoft.com/technet/security/advisory/932114.mspxVendor Advisory
- http://www.securityfocus.com/bid/22225
- http://www.securityfocus.com/bid/22328
- http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html
- http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html
- http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2
- http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0350Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31834
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A528
- http://isc.sans.org/diary.html?storyid=2133
- http://osvdb.org/31900
- http://secunia.com/advisories/23950Vendor Advisory
- http://securitytracker.com/id?1017564
- http://www.kb.cert.org/vuls/id/412225US Government Resource
- http://www.microsoft.com/technet/security/advisory/932114.mspxVendor Advisory
- http://www.securityfocus.com/bid/22225
- http://www.securityfocus.com/bid/22328
- http://www.symantec.com/enterprise/security_response/weblog/2007/01/multiple_organizations_targett.html
- http://www.symantec.com/enterprise/security_response/weblog/2007/01/new_microsoft_word_2000_vulner.html
- http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-013010-5422-99&tabid=2
- http://www.us-cert.gov/cas/techalerts/TA07-044A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/0350Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-014
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.