CVE-2007-2223

Description

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

Risk Information

Base Score
8.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
68.203

Associated Vulnerability

VulnerabilityOS Platform
Security Update for Windows 2000 (KB936021)Windows
Security Update for Microsoft XML Core Services 4.0 Service Pack 2 (KB936181)Windows
Security Update for Microsoft XML Core Services 6.0 and Service Pack 1 (KB933579)Windows
Security Update for Windows XP (KB936021)Windows
Security Update for Windows Server 2003 (KB936021)Windows
Security Update for Windows Vista (KB936021)Windows
Security Update for Windows Vista (KB933579)Windows
Security Update for Office 2003 (KB936048)Windows
Security Update for the 2007 Microsoft Office System (KB936960)Windows
Security Update for Windows Vista for x64-based Systems (KB936021)Windows
Security Update for Windows Vista for x64-based Systems (KB933579)Windows
Security Update for Windows XP x64 Edition (KB936021)Windows
Security Update for Windows XP x64 Edition (KB933579)Windows

Patch Details

Click to see the patches provided by ManageEngine for this CVE
Patch IDPatch Description
PATCH-1723Security Update for Windows Server 2003 (KB936021)
PATCH-5356Security Update for Windows XP x64 Edition (KB936021)

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234