CVE-2007-1083
Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (8.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Buffer overflow in the Configuration Checker (ConfigChk) ActiveX control in VSCnfChk.dll 2.0.0.2 for Verisign Managed PKI Service, Secure Messaging for Microsoft Exchange, and Go Secure! allows remote attackers to execute arbitrary code via long arguments to the VerCompare method.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 8.23% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- verisign/mpki
- Source
- cve@mitre.org
References
- http://attrition.org/pipermail/vim/2007-February/001384.html
- http://attrition.org/pipermail/vim/2007-February/001385.html
- http://jvn.jp/cert/JVNVU%23308087/index.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479
- http://osvdb.org/33479
- http://secunia.com/advisories/24249Vendor Advisory
- http://www.jpcert.or.jp/at/2007/at070006.txt
- http://www.kb.cert.org/vuls/id/308087US Government Resource
- http://www.securityfocus.com/bid/22671
- http://www.securityfocus.com/bid/22676
- http://www.securitytracker.com/id?1017692
- http://www.securitytracker.com/id?1017693
- http://www.securitytracker.com/id?1017694
- http://www.vupen.com/english/advisories/2007/0702
- https://download.verisign.co.jp/support/announce/20070216.htmlVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/32639
- http://attrition.org/pipermail/vim/2007-February/001384.html
- http://attrition.org/pipermail/vim/2007-February/001385.html
- http://jvn.jp/cert/JVNVU%23308087/index.html
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=479
- http://osvdb.org/33479
- http://secunia.com/advisories/24249Vendor Advisory
- http://www.jpcert.or.jp/at/2007/at070006.txt
- http://www.kb.cert.org/vuls/id/308087US Government Resource
- http://www.securityfocus.com/bid/22671
- http://www.securityfocus.com/bid/22676
- http://www.securitytracker.com/id?1017692
- http://www.securitytracker.com/id?1017693
- http://www.securitytracker.com/id?1017694
- http://www.vupen.com/english/advisories/2007/0702
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.