Vulnerabilities > CVE-2007-0026 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 3 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS07-011.NASL |
description | The remote host contains a version of Microsoft Windows that has a vulnerability in the OLE Dialog component that could be abused by an attacker to execute arbitrary code on the remote host. To exploit this vulnerability, an attacker would need to send a specially crafted RTF file to a user on the remote host and lure him into opening it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 24335 |
published | 2007-02-13 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/24335 |
title | MS07-011: Vulnerability in Microsoft OLE Dialog Could Allow Remote Code Execution (926436) |
code |
|
Oval
accepted | 2007-04-10T13:44:26.598-04:00 | ||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||
contributors |
| ||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||
description | The OLE Dialog component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1 allows user-assisted remote attackers to execute arbitrary code via an RTF file with a malformed OLE object that triggers memory corruption. | ||||||||||||||||||||
family | windows | ||||||||||||||||||||
id | oval:org.mitre.oval:def:540 | ||||||||||||||||||||
status | accepted | ||||||||||||||||||||
submitted | 2007-02-14T09:49:32 | ||||||||||||||||||||
title | OLE Dialog Memory Corruption Vulnerability | ||||||||||||||||||||
version | 70 |
References
- http://secunia.com/advisories/24147
- http://www.kb.cert.org/vuls/id/497756
- http://www.osvdb.org/31885
- http://www.securityfocus.com/bid/22483
- http://www.securitytracker.com/id?1017637
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.vupen.com/english/advisories/2007/0580
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-011
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A540
- http://secunia.com/advisories/24147
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A540
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-011
- http://www.vupen.com/english/advisories/2007/0580
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.securitytracker.com/id?1017637
- http://www.securityfocus.com/bid/22483
- http://www.osvdb.org/31885
- http://www.kb.cert.org/vuls/id/497756