CVE-2007-2238
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 45.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 45.53% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/intelligent application gateway 2007
- Source
- cret@cert.org
References
- http://secunia.com/advisories/34725
- http://www.kb.cert.org/vuls/id/789121US Government Resource
- http://www.securityfocus.com/bid/34532Patch
- http://www.vupen.com/english/advisories/2009/1061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49888
- http://secunia.com/advisories/34725
- http://www.kb.cert.org/vuls/id/789121US Government Resource
- http://www.securityfocus.com/bid/34532Patch
- http://www.vupen.com/english/advisories/2009/1061
- https://exchange.xforce.ibmcloud.com/vulnerabilities/49888
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.