CVE-2007-1749

Description

Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in Internet Explorer 5.01, 6, and 7 allows remote attackers to execute arbitrary code via compressed content with an invalid buffer size, which triggers a heap-based buffer overflow.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
78.27

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Internet Explorer 5.01 Service Pack 4 (KB938127)Windows
Security Update for Internet Explorer 6 SP1 (KB938127)Windows
Security Update for Internet Explorer for Windows XP (KB938127)Windows
Security Update for Internet Explorer for Windows Server 2003 (KB938127) x86 based systemsWindows
Security Update for Internet Explorer for Windows Server 2003 (KB938127) x86 based systems for SP2Windows
Security Update for Internet Explorer 7 for Windows XP (KB938127)Windows
Security Update for Internet Explorer 7 for Windows Server 2003 (KB938127) x86 based systemsWindows
Security Update for Internet Explorer 7 for Windows Server 2003 (KB938127) x86 based systems for SP2Windows
Security Update for Internet Explorer 7 in Windows Vista (KB938127)Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB938127)Windows
Security Update for Internet Explorer for Windows XP x64 Edition (KB938127)Windows
Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB938127)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1757Security Update for Internet Explorer for Windows XP (KB938127)
PATCH-1758Security Update for Internet Explorer for Windows Server 2003 (KB938127)
PATCH-1759Security Update for Internet Explorer for Windows Server 2003 (KB938127)
PATCH-1760Security Update for Internet Explorer 7 for Windows XP (KB938127)
PATCH-1761Security Update for Internet Explorer 7 for Windows Server 2003 (KB938127)
PATCH-1762Security Update for Internet Explorer 7 for Windows Server 2003 (KB938127)
PATCH-5349Security Update for Internet Explorer for Windows XP x64 Edition (KB938127)
PATCH-5350Security Update for Internet Explorer 7 for Windows XP x64 Edition (KB938127)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234