PT-2007-4433 · Google · Google Desktop

Published

2007-06-11

·

Updated

2008-11-15

·

CVE-2007-3150

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Google Desktop (affected versions not specified)
Description: The issue allows remote attackers to execute arbitrary programs via a man-in-the-middle attack. This attack involves injecting JavaScript, a www.google.com search IFRAME, and a META HTTP-EQUIV="refresh" that targets a www.google.com search for a local .exe file. The .exe file is displayed in the search results and, when clicked, invokes Google Desktop to execute the file.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-3150

Affected Products

Google Desktop