VulnerabilityModified
CVE-2007-2223
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
HIGH 9.3EPSS 48.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 48.7%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 48.72% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-190
- Affected
- microsoft/xml core services
- Source
- secure@microsoft.com
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576Broken Link
- http://secunia.com/advisories/26447Vendor Advisory
- http://www.kb.cert.org/vuls/id/361968Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/476527/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/476747/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25301Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018559Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2866Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-048/Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2069Third Party Advisory
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576Broken Link
- http://secunia.com/advisories/26447Vendor Advisory
- http://www.kb.cert.org/vuls/id/361968Third Party Advisory, US Government Resource
- http://www.securityfocus.com/archive/1/476527/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/archive/1/476747/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/25301Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018559Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/2866Vendor Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-07-048/Third Party Advisory, VDB Entry
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042Patch, Vendor Advisory
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2069Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.