PT-2007-3555 · Microsoft · Tblinf32.Dll+2
Published
2007-08-14
·
Updated
2021-07-23
·
CVE-2007-2216
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 5.01, 6 SP1, and 7
Description
The issue allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the
TypeLibInfoFromFile function. This is due to an incorrect IObjectsafety implementation in the tblinf32.dll (also known as vstlbinf.dll) ActiveX control. An attacker could exploit this by constructing a specially crafted Web page, potentially allowing remote code execution if a user visits the page, and could gain the same user rights as the logged-on user.Recommendations
For Internet Explorer versions 5.01, 6 SP1, and 7, consider disabling the
tblinf32.dll (aka vstlbinf.dll) ActiveX control to prevent exploitation until a patch is available.
As a temporary workaround, restrict access to Web pages that could potentially exploit this issue to minimize the risk of remote code execution.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Internet Explorer
Tblinf32.Dll
Vstlbinf.Dll