Vulnerability Name: CVE-2007-0024 (CCN-31287) Assigned: 2007-01-09 Published: 2007-01-09 Updated: 2021-07-23 Summary: Integer overflow in the Vector Markup Language (VML) implementation (vgx.dll) in Microsoft Internet Explorer 5.01, 6, and 7 on Windows 2000 SP4, XP SP2, Server 2003, and Server 2003 SP1 allows remote attackers to execute arbitrary code via a crafted web page that contains unspecified integer properties that cause insufficient memory allocation and trigger a buffer overflow, aka the "VML Buffer Overrun Vulnerability." CVSS v3 Severity: 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): HighPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): ChangedImpact Metrics: Confidentiality (C): HighIntegrity (I): HighAvailibility (A): High
CVSS v2 Severity: 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C )7.7 High (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): MediumAuthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
7.6 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C )6.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C/E:F/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): HighAthentication (Au): NoneImpact Metrics: Confidentiality (C): CompleteIntegrity (I): CompleteAvailibility (A): Complete
Vulnerability Type: CWE-Other Vulnerability Consequences: Gain Access References: Source: MITRE Type: CNACVE-2007-0024 Source: IDEFENSE Type: Patch, Vendor Advisory20070109 Microsoft Windows VML Element Integer Overflow Vulnerability Source: CCN Type: SA23677Microsoft Windows Vector Markup Language Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory23677 Source: CCN Type: SECTRACK ID: 1017489Windows Vector Markup Language Buffer Overflow Lets Remote Users Execute Arbitrary Code Source: SECTRACK Type: Patch1017489 Source: CONFIRM Type: UNKNOWNhttp://support.avaya.com/elmodocs2/security/ASA-2007-009.htm Source: CCN Type: ASA-2007-009MS07-004 Vulnerability in Vector Markup Language Could Allow Remote Code Execution (929969) Source: MSKB Type: Patch929969 Source: CCN Type: Microsoft Security Bulletin MS11-096Vulnerability in Microsoft Excel Could Allow Remote Code Execution (2640241) Source: CCN Type: Microsoft Security Bulletin MS12-028Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2639185) Source: CCN Type: Microsoft Security Bulletin MS12-029Vulnerability in Microsoft Word Could Allow Remote Code Execution (2680352) Source: CCN Type: Microsoft Security Bulletin MS12-034Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) Source: CCN Type: Microsoft Security Bulletin MS12-057Vulnerability in Microsoft Office Could Allow for Remote Code Execution (2731879) Source: CCN Type: Microsoft Security Bulletin MS12-064Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2742319) Source: CCN Type: Microsoft Security Bulletin MS12-065Vulnerability in Microsoft Works Could Allow Remote Code Execution (KB2754670) Source: CCN Type: Microsoft Security Bulletin MS12-070Vulnerability in SQL Server Could Allow Elevation of Privilege (2754849) Source: CCN Type: Microsoft Security Bulletin MS12-079Vulnerability in Microsoft Word Could Allow Remote Code Execution (2780642) Source: CCN Type: Microsoft Security Bulletin MS13-022Vulnerability in Silverlight Could Allow Remote Code Execution (2814124) Source: CCN Type: Microsoft Security Bulletin MS13-043Vulnerability in Microsoft Word Could Allow Remote Code Execution (2830399) Source: CCN Type: Microsoft Security Bulletin MS13-054Vulnerability in Windows Components Could Allow Remote Code Execution (2848295) Source: CCN Type: Microsoft Security Bulletin MS13-072Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2845537) Source: CCN Type: Microsoft Security Bulletin MS13-085Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2885080) Source: CCN Type: Microsoft Security Bulletin MS13-086Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2885084) Source: CCN Type: Microsoft Security Bulletin MS14-001Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2916605) Source: CCN Type: Microsoft Security Bulletin MS14-017Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (2949660) Source: CCN Type: Microsoft Security Bulletin MS14-034Vulnerability in Microsoft Word Could Allow Remote Code Execution (2969261) Source: CCN Type: Microsoft Security Bulletin MS14-038Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) Source: CCN Type: Microsoft Security Bulletin MS14-044Vulnerabilities in SQL Server Could Allow Elevation of Privilege (2984340) Source: CCN Type: Microsoft Security Bulletin MS14-061Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3000434) Source: CCN Type: Microsoft Security Bulletin MS14-069Vulnerability in Microsoft Office Could Allow Remote Code Execution (3009710) Source: CCN Type: Microsoft Security Bulletin MS14-081Vulnerabilities in Microsoft Word and Office Web Apps Could Allow Remote Code Execution (3017301) Source: CCN Type: Microsoft Security Bulletin MS14-083Vulnerabilities in MicrosoftExcel Could Allow Remote Code Execution (3017347) Source: CCN Type: Microsoft Security Bulletin MS15-081Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3080790) Source: CCN Type: Microsoft Security Bulletin MS15-099Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (3089664) Source: CCN Type: Microsoft Security Bulletin MS15-110Security Updates for Microsoft Office (3096440) Source: CCN Type: Microsoft Security Bulletin MS15-116Security Updates for Microsoft Office to Address Remote Code Execution (3104540) Source: CCN Type: Microsoft Security Bulletin MS15-131Security Update for Microsoft Office to Address Remote Code Execution (3116111) Source: CCN Type: Microsoft Security Bulletin MS16-004Security Update for Microsoft Office to Address Remote Code Execution - Critical (3124585) Source: CCN Type: Microsoft Security Bulletin MS16-015Security Update for Microsoft Office to Address Remote Code Execution (3134226) Source: CCN Type: Microsoft Security Bulletin MS16-029Security Update for Microsoft Office to Address Remote Code Execution (3141806) Source: CCN Type: Microsoft Security Bulletin MS16-042Security Update for Microsoft Office (3148775) Source: CCN Type: Microsoft Security Bulletin MS16-054Security Update for Microsoft Office (3155544) Source: CCN Type: Microsoft Security Bulletin MS16-070Security Update for Office (3163610) Source: CCN Type: Microsoft Security Bulletin MS16-088Security Updates for Office (3170008) Source: CCN Type: Microsoft Security Bulletin MS16-099Security Update for Office (3177451) Source: CCN Type: Microsoft Security Bulletin MS16-107Security Update for Microsoft Office (3185852) Source: CCN Type: Microsoft Security Bulletin MS16-121Security Update for Microsoft Office (3194063) Source: CCN Type: Microsoft Security Bulletin MS16-133Security Update for Microsoft Office (3199168) Source: CCN Type: Microsoft Security Bulletin MS16-148Security Update for Microsoft Office (3204068) Source: CCN Type: Microsoft Security Bulletin MS17-002Security Update for Microsoft Office (3214291) Source: CCN Type: Microsoft Security Bulletin MS17-013Security Update for Microsoft Graphics Component (4013075) Source: CCN Type: Microsoft Security Bulletin MS17-014Security Update for Microsoft Office (4013241) Source: CCN Type: US-CERT VU#122084Microsoft Internet Explorer VML buffer overflow Source: CERT-VN Type: Patch, US Government ResourceVU#122084 Source: CCN Type: Microsoft Security Bulletin MS07-004Vulnerability in Vector Markup Language Could Allow Remote Code Execution (929969) Source: CCN Type: Microsoft Security Bulletin MS07-050Vulnerability in Vector Markup Language Could Allow Remote Code Execution (938127) Source: CCN Type: Microsoft Security Bulletin MS08-052Vulnerabilities in GDI+ Could Allow Remote Code Execution (954593) Source: CCN Type: Microsoft Security Bulletin MS09-004Vulnerability in Microsoft SQL Server Could Allow Remote Code Execution (959420) Source: CCN Type: Microsoft Security Bulletin MS09-017Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (967340) Source: CCN Type: Microsoft Security Bulletin MS09-062Vulnerabilities in GDI+ Could Allow Remote Code Execution (957488) Source: CCN Type: Microsoft Security Bulletin MS10-003Vulnerability in Microsoft Office (MSO) Could Allow Remote Code Execution (978214) Source: CCN Type: Microsoft Security Bulletin MS10-004Vulnerabilities in Microsoft Office PowerPoint Could Allow Remote Code Execution (975416) Source: CCN Type: Microsoft Security Bulletin MS10-028Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (980094) Source: CCN Type: Microsoft Security Bulletin MS10-036Vulnerabilities in COM validation in Microsoft Office Could Allow Remote Code Execution (983235 Source: CCN Type: Microsoft Security Bulletin MS10-056Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution (2269638) Source: CCN Type: Microsoft Security Bulletin MS10-057Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution (2269707) Source: CCN Type: Microsoft Security Bulletin MS10-079Vulnerabilities in Microsoft Word Could Allow Remote Code Execution (2293194) Source: CCN Type: Microsoft Security Bulletin MS10-087Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2423930) Source: CCN Type: Microsoft Security Bulletin MS10-105Vulnerabilities in Microsoft Office Graphics Filters Could Allow for Remote Code Execution (968095) Source: CCN Type: Microsoft Security Bulletin MS11-008Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2451879) Source: CCN Type: Microsoft Security Bulletin MS11-021Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2489279) Source: CCN Type: Microsoft Security Bulletin MS11-023Vulnerabilities in Microsoft Office Could Allow Remote Code Execution (2489293) Source: CCN Type: Microsoft Security Bulletin MS11-029Vulnerability in GDI+ Could Allow Remote Code Execution (2489979) Source: CCN Type: Microsoft Security Bulletin MS11-045Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2537146) Source: CCN Type: Microsoft Security Bulletin MS11-049Vulnerability in the Microsoft XML Editor Could Allow Information Disclosure (2543893) Source: CCN Type: Microsoft Security Bulletin MS11-060Vulnerabilities in Microsoft Visio Could Allow Remote Code Execution (2560978) Source: CCN Type: Microsoft Security Bulletin MS11-072Vulnerabilities in Microsoft Excel Could Allow Remote Code Execution (2587505) Source: OSVDB Type: Patch31250 Source: CCN Type: OSVDB ID: 31250Microsoft IE Vector Markup Language (VML) Overflow Source: BUGTRAQ Type: UNKNOWN20070116 MS07-004 VML Integer Overflow Exploit Source: BUGTRAQ Type: UNKNOWN20070117 Re: MS07-004 VML Integer Overflow Exploit Source: HP Type: UNKNOWNHPSBST02184 Source: BID Type: Patch21930 Source: CCN Type: BID-21930Microsoft Windows Vector Markup Language Buffer Overrun Vulnerability Source: CERT Type: US Government ResourceTA07-009A Source: VUPEN Type: UNKNOWNADV-2007-0105 Source: VUPEN Type: UNKNOWNADV-2007-0129 Source: MS Type: UNKNOWNMS07-004 Source: XF Type: UNKNOWNie-vml-record-bo(31287) Source: XF Type: UNKNOWNie-vml-record-bo(31287) Source: CCN Type: iDefense Labs PUBLIC ADVISORY: 01.09.07Microsoft Windows VML Element Integer Overflow Vulnerability Source: OVAL Type: UNKNOWNoval:org.mitre.oval:def:1058 Vulnerable Configuration: Configuration 1 :cpe:/o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* AND cpe:/a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* Configuration 2 :cpe:/o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* AND cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:* Configuration 3 :cpe:/o:microsoft:windows_xp:*:*:64-bit:*:*:*:*:* OR cpe:/o:microsoft:windows_xp:*:sp2:*:*:*:*:*:* AND cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* Configuration 4 :cpe:/o:microsoft:windows_2003_server:*:*:itanium:*:*:*:*:* OR cpe:/o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_2003_server:*:*:*:*:*:*:*:* OR cpe:/o:microsoft:windows_2003_server:*:*:64-bit:*:*:*:*:* OR cpe:/o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:* AND cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:microsoft:ie:6.0:sp1:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:* OR cpe:/a:microsoft:internet_explorer:7.0:*:*:*:*:*:*:* AND cpe:/o:microsoft:windows_2000:-:sp4:*:*:*:*:*:* OR cpe:/o:microsoft:windows:2003_server::x64:*:*:*:*:* OR cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:* OR cpe:/o:microsoft:windows_2003_server:-::~~~~itanium~:*:*:*:*:* OR cpe:/o:microsoft:windows:2003_server:sp1:*:*:*:*:*:* OR cpe:/o:microsoft:windows:2003_server:sp1_itanium:*:*:*:*:*:* Denotes that component is vulnerable Oval Definitions Definition ID Class Title Last Modified oval:org.mitre.oval:def:1058 V Vulnerability in Vector Markup Language (VML) Could Allow Remote Code Execution 2008-05-05
BACK
microsoft windows 2000 * sp4
microsoft internet explorer 5.01 sp4
microsoft windows 2000 * sp4
microsoft ie 6.0 sp1
microsoft windows xp *
microsoft windows xp * sp2
microsoft internet explorer 7.0
microsoft windows 2003 server *
microsoft windows 2003 server sp1
microsoft windows 2003 server *
microsoft windows 2003 server *
microsoft windows 2003 server sp1
microsoft internet explorer 7.0
microsoft ie 6.0 sp1
microsoft ie 5.01 sp4
microsoft ie 7.0
microsoft windows 2000 - sp4
microsoft windows 2003_server
microsoft windows xp sp2
microsoft windows 2003 server -
microsoft windows 2003_server sp1
microsoft windows 2003_server sp1_itanium