First published: Tue May 08 2007(Updated: )
Unspecified vulnerability in Microsoft Internet Explorer 7 on Windows XP SP2, Windows Server 2003 SP1 or SP2, or Windows Vista allows remote attackers to execute arbitrary code via crafted HTML objects, which results in memory corruption, aka the first of two "HTML Objects Memory Corruption Vulnerabilities" and a different issue than CVE-2007-0947.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 | |
Internet Explorer | =7.0 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =sp2 | |
Microsoft Windows Vista |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0946 is classified as a critical vulnerability due to its potential for remote code execution.
To mitigate CVE-2007-0946, it is recommended to apply the latest security updates from Microsoft for Internet Explorer and the affected Windows operating systems.
CVE-2007-0946 affects users of Microsoft Internet Explorer 7 running on Windows XP SP2, Windows Server 2003 SP1 or SP2, and Windows Vista.
Exploitation of CVE-2007-0946 can lead to arbitrary code execution, allowing attackers to take complete control of the affected system.
Although CVE-2007-0946 was disclosed in 2007, systems still running the affected software versions are at risk and should be updated immediately.