Vulnerability Name:

CVE-2007-1201 (CCN-35213)

Assigned:2007-03-02
Published:2008-03-11
Updated:2018-10-12
Summary:Unspecified vulnerability in certain COM objects in Microsoft Office Web Components 2000 allows user-assisted remote attackers to execute arbitrary code via vectors related to DataSource that trigger memory corruption, aka "Office Web Components DataSource Vulnerability."
CVSS v3 Severity:10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
9.3 High (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-94
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2007-1201

Source: HP
Type: UNKNOWN
SSRT080028

Source: CCN
Type: SA29328
Microsoft Office Web Components Two Vulnerabilities

Source: SECUNIA
Type: Vendor Advisory
29328

Source: CCN
Type: SECTRACK ID: 1019581
Microsoft Office Web Components DataSource Bug Lets Remote Users Execute Arbitrary Code

Source: CCN
Type: ASA-2008-117
MS08-017 Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (933103)

Source: CCN
Type: Microsoft Security Bulletin MS08-017
Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (933103)

Source: CCN
Type: Microsoft Security Bulletin MS09-043
Vulnerabilities in Microsoft Office Web Components Could Allow Remote Code Execution (957638)

Source: BID
Type: Patch
28136

Source: CCN
Type: BID-28136
Microsoft Office Web Components ActiveX Control DataSource Remote Code Execution Vulnerability

Source: SECTRACK
Type: UNKNOWN
1019581

Source: CERT
Type: US Government Resource
TA08-071A

Source: VUPEN
Type: UNKNOWN
ADV-2008-0849

Source: MS
Type: UNKNOWN
MS08-017

Source: XF
Type: UNKNOWN
ms-owc-virtualcall-bo(35213)

Source: OVAL
Type: UNKNOWN
oval:org.mitre.oval:def:5327

Vulnerable Configuration:Configuration 1:
  • cpe:/a:microsoft:biztalk_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:biztalk_server:2002:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:commerce_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:internet_security_and_acceleration_server:2000:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_.net:2002:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio_.net:2003:sp1:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:microsoft:office_web_components:2000:*:*:*:*:*:*:*
  • AND
  • cpe:/a:microsoft:commerce_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:biztalk_server:2000:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:biztalk_server:2002:*:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:xp:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:office:2000:sp3:*:*:*:*:*:*
  • OR cpe:/a:microsoft:isa_server:2000:sp2:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio:2003:sp1:*:*:*:*:*:*
  • OR cpe:/a:microsoft:visual_studio:2002:sp1:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.mitre.oval:def:5327
    V
    Office Web Components DataSource Vulnerability
    2014-06-30
    BACK
    microsoft biztalk server 2000
    microsoft biztalk server 2002
    microsoft commerce server 2000
    microsoft internet security and acceleration server 2000 sp2
    microsoft office 2000 sp3
    microsoft office xp sp3
    microsoft visual studio .net 2002 sp1
    microsoft visual studio .net 2003 sp1
    microsoft office web components 2000
    microsoft commerce server 2000
    microsoft biztalk server 2000
    microsoft biztalk server 2002
    microsoft office xp sp3
    microsoft office 2000 sp3
    microsoft isa server 2000 sp2
    microsoft visual studio 2003 sp1
    microsoft visual studio 2002 sp1