SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-1499

Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location…

MEDIUM 4.3EPSS 29.8%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 29.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.

Description

Microsoft Internet Explorer 7.0 on Windows XP and Vista allows remote attackers to conduct phishing attacks and possibly execute arbitrary code via a res: URI to navcancl.htm with an arbitrary URL as an argument, which displays the URL in the location bar of the "Navigation Canceled" page and injects the script into the "Refresh the page" link, aka Navigation Cancel Page Spoofing Vulnerability."

CVSS 2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
29.78% probability · 98th percentile
CISA KEV
Not listed
Weakness
CWE-79
Affected
microsoft/ie
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.