PT-2007-2383 · Microsoft · Windows Vista+4

Published

2007-05-08

·

Updated

2021-07-23

·

CVE-2007-0946

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Internet Explorer 7 versions on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista
Description: The issue allows remote attackers to execute arbitrary code via crafted HTML objects, resulting in memory corruption. Several remote code execution vulnerabilities exist due to attempts to access uninitialized memory in certain situations. An attacker could exploit these vulnerabilities by constructing a specially crafted Web page, potentially allowing remote code execution and complete control of an affected system.
Recommendations: For Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista, consider restricting access to crafted HTML objects until a patch is available. As a temporary workaround, avoid viewing specially crafted Web pages with Internet Explorer 7 on these operating systems until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-0946

Affected Products

Internet Explorer
Internet Explorer 7
Windows Server 2003
Windows Vista
Windows Xp