CVE-2007-1784
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.47%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The JNILoader ActiveX control (STJNILoader.ocx) 3.1.0.26 in IBM Lotus Notes Sametime before 7.5 allows remote attackers to load arbitrary DLL libraries and execute arbitrary code via arbitrary arguments to the loadLibrary function.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.47% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- ibm/lotus sametime
- Source
- cve@mitre.org
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=495
- http://www-1.ibm.com/support/docview.wss?uid=swg21257029Vendor Advisory
- http://www.securityfocus.com/bid/23201
- http://www.securitytracker.com/id?1017828
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33314
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=495
- http://www-1.ibm.com/support/docview.wss?uid=swg21257029Vendor Advisory
- http://www.securityfocus.com/bid/23201
- http://www.securitytracker.com/id?1017828
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33314
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.