PT-2007-2129 · Microsoft · Windows Vista+2
Published
2007-02-03
·
Updated
2018-10-12
·
CVE-2007-0675
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista (affected versions not specified)
Description
The issue concerns a certain ActiveX control in sapi.dll, which is part of the Speech Components in Microsoft Windows. When the Speech Recognition feature is enabled, it allows remote attackers to perform unauthorized activities, including deleting arbitrary files. This can be achieved through a web page with an embedded sound object containing voice commands, which interact with an enabled microphone and subsequently with Windows Explorer.
Recommendations
For Microsoft Windows Vista, consider disabling the Speech Recognition feature until a fix is available. As a temporary workaround, restrict access to the microphone when the Speech Recognition feature is enabled to minimize the risk of exploitation. Avoid interacting with Windows Explorer via voice commands from web pages with embedded sound objects.
Fix
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Explorer
Windows Vista
Sapi.Dll