First published: Tue Jun 12 2007(Updated: )
Microsoft Internet Explorer 5.01 and 6 allows remote attackers to execute arbitrary code by instantiating certain COM objects from Urlmon.dll, which triggers memory corruption during a call to the IObjectSafety function.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
Internet Explorer | =5.01-sp4 | |
Internet Explorer | =6-sp1 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Internet Explorer | =6 | |
Internet Explorer | =7.0 | |
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Vista | =gold | |
Microsoft Windows Vista | =gold |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0218 is classified as a critical vulnerability due to its potential for remote code execution.
To remediate CVE-2007-0218, users should upgrade to a newer, unsupported version of Internet Explorer and apply all relevant security updates.
CVE-2007-0218 affects Internet Explorer versions 5.01 and 6, specifically with SP4 and SP1.
Yes, CVE-2007-0218 can be exploited remotely by attackers to execute arbitrary code on the affected systems.
Disabling scripting and ActiveX controls in Internet Explorer may reduce the risk of exploitation from CVE-2007-0218.