PT-2007-3555 · Microsoft · Tblinf32.Dll+2

Published

2007-08-14

·

Updated

2021-07-23

·

CVE-2007-2216

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Internet Explorer versions 5.01, 6 SP1, and 7
Description The issue allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function. This is due to an incorrect IObjectsafety implementation in the tblinf32.dll (also known as vstlbinf.dll) ActiveX control. An attacker could exploit this by constructing a specially crafted Web page, potentially allowing remote code execution if a user visits the page, and could gain the same user rights as the logged-on user.
Recommendations For Internet Explorer versions 5.01, 6 SP1, and 7, consider disabling the tblinf32.dll (aka vstlbinf.dll) ActiveX control to prevent exploitation until a patch is available. As a temporary workaround, restrict access to Web pages that could potentially exploit this issue to minimize the risk of remote code execution.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2007-2216

Affected Products

Internet Explorer
Tblinf32.Dll
Vstlbinf.Dll