PT-2007-3556 · Microsoft+1 · Windows 2000+4

Publicado

2007-10-09

·

Atualizado

2018-10-16

·

CVE-2007-2217

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Kodak Image Viewer in Microsoft Windows versions 2000 SP4, XP SP2, Server 2003 SP1, and Server 2003 SP2
Description A remote code execution issue exists in the way the Kodak Image Viewer handles specially crafted image files, potentially allowing an attacker to execute arbitrary code via crafted image files that trigger memory corruption. This could be exploited if a user visits a Web site, views a specially crafted e-mail message, or opens an e-mail attachment, potentially allowing an attacker to take complete control of an affected system.
Recommendations For Windows 2000 SP4, update the Kodak Image Viewer to a version that is not affected by this issue. For Windows XP SP2, consider disabling the Kodak Image Viewer until a patch is available. For Windows Server 2003 SP1 and SP2, restrict access to the Kodak Image Viewer to minimize the risk of exploitation.

Exploit

Correção

RCE

Code Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2007-2217

Produtos afetados

Kodak Image Viewer
Windows
Windows 2000
Windows Server 2003
Windows Xp