CVE-2007-2223: Buffer Overflow
Published Aug 14, 2007
·Updated
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
Affected Software
25 affected components
Microsoft XML Core Services=3.0
Microsoft XML Core Services=4.0
Microsoft XML Core Services=6.0
Microsoft Windows Server 2003
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp1
Microsoft Windows Server 2003=sp2
Microsoft Windows Vista
Microsoft Windows Vista
Microsoft Windows Vista=gold
Microsoft Windows Vista=sp1
Microsoft Windows XP
Microsoft Windows XP=sp2
Microsoft Windows XP=sp2
Microsoft Windows XP=sp3
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft XML Core Services=5.0
Microsoft Expression Web
Microsoft Office=2003-sp2
Microsoft Office=2007
Microsoft Office Compatibility Pack=2007
Microsoft Office Groove Server=2007
Microsoft Office SharePoint Server
Microsoft Word Viewer=2003
Remediation
Event History
Aug 14, 2007
CVE Published
09:17 PM
Data Sourced
09:17 PM
DescriptionWeaknessAffected Software
Aug 15, 2007
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-2223?
CVE-2007-2223 is considered a critical vulnerability that allows remote code execution.
2
How do I fix CVE-2007-2223?
To mitigate CVE-2007-2223, users should update Microsoft XML Core Services to a patched version.
3
What versions of Microsoft XML Core Services are affected by CVE-2007-2223?
CVE-2007-2223 affects Microsoft XML Core Services versions 3.0, 4.0, 5.0, and 6.0.
4
Can CVE-2007-2223 be exploited remotely?
Yes, CVE-2007-2223 can be exploited remotely via the substringData method.
5
What systems are primarily at risk for CVE-2007-2223?
Systems running vulnerable versions of Microsoft XML Core Services and certain related applications are at risk for CVE-2007-2223.