CVE-2007-0948
Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 12.1%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Heap-based buffer overflow in Microsoft Virtual PC 2004 and PC for Mac 7.1 and 7, and Virtual Server 2005 and 2005 R2, allows local guest OS administrators to execute arbitrary code on the host OS via unspecified vectors related to "interaction and initialization of components."
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 12.13% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/virtual pc · microsoft/virtual server
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/26444Vendor Advisory
- http://www.securityfocus.com/bid/25298Patch
- http://www.securitytracker.com/id?1018567
- http://www.us-cert.gov/cas/techalerts/TA07-226A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2873
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-049
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1259
- http://secunia.com/advisories/26444Vendor Advisory
- http://www.securityfocus.com/bid/25298Patch
- http://www.securitytracker.com/id?1018567
- http://www.us-cert.gov/cas/techalerts/TA07-226A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2873
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-049
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1259
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.