CVE-2007-0033: Critical severity Microsoft Outlook vulnerability
Published Jan 9, 2007
·Updated
Microsoft Outlook 2002 and 2003 allows user-assisted remote attackers to execute arbitrary code via a malformed VEVENT record in an .iCal meeting request or ICS file.
Affected Software
6 affected components
Microsoft Outlook=2000
Microsoft Office=2000-sp3
Microsoft Office=xp-sp3
Microsoft Outlook=2002
Microsoft Outlook=2003
Microsoft Office=2003-sp2
Event History
Jan 9, 2007
CVE Published
11:28 PM
Jan 10, 2007
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0033?
CVE-2007-0033 is considered a critical vulnerability as it allows remote attackers to execute arbitrary code.
2
How do I fix CVE-2007-0033?
To remedy CVE-2007-0033, users should apply the latest security patches provided by Microsoft for affected Outlook and Office versions.
3
Which software versions are affected by CVE-2007-0033?
CVE-2007-0033 affects Microsoft Outlook 2002, 2003, Office 2000, and Office XP SP3.
4
What type of attack is associated with CVE-2007-0033?
CVE-2007-0033 is associated with user-assisted remote code execution attacks via malformed iCal meeting requests.
5
Can CVE-2007-0033 compromise my organization?
Yes, if exploited, CVE-2007-0033 can lead to unauthorized access and control over systems within an organization.