CVE-2007-2240
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded…
Does this matter?
Lower severity and a low EPSS score (2.64%). Track it; it rarely justifies an emergency change on its own.
Description
The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.
- CVSS 2.0
- 5.8 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- lenovo/access support · lenovo/automated solutions
- Source
- cret@cert.org
References
- http://osvdb.org/39555
- http://secunia.com/advisories/26482
- http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649
- http://www.kb.cert.org/vuls/id/570705US Government Resource
- http://www.securityfocus.com/bid/25311
- http://www.vupen.com/english/advisories/2007/2882
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36028
- http://osvdb.org/39555
- http://secunia.com/advisories/26482
- http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649
- http://www.kb.cert.org/vuls/id/570705US Government Resource
- http://www.securityfocus.com/bid/25311
- http://www.vupen.com/english/advisories/2007/2882
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36028
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.