Vulnerabilities > CVE-2007-2219 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 10 |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS07-035.NASL |
description | The remote host contains a version of the Win32 API that is vulnerable to a security flaw that could allow a local user to gain elevated privileges, and might allow a remote attacker to execute arbitrary code on the host. To exploit the flaw, an attacker would need to find a way to misuse the Win32 API. One way of doing so would be to lure a user on the remote host into visiting a specially crafted web page. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 25488 |
published | 2007-06-12 |
reporter | This script is Copyright (C) 2007-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/25488 |
title | MS07-035: Vulnerability in Win 32 API Could Allow Remote Code Execution (935839) |
code |
|
Oval
accepted | 2012-09-10T04:00:39.549-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Unspecified vulnerability in the Win32 API on Microsoft Windows 2000, XP SP2, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via certain parameters to an unspecified function. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:1643 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2007-06-12T03:29:54.000-04:00 | ||||||||||||||||||||||||
title | Win32 API Remote Code Execution Vulnerability | ||||||||||||||||||||||||
version | 73 |
References
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
- http://www.kb.cert.org/vuls/id/457281
- http://www.securityfocus.com/bid/24370
- http://www.securitytracker.com/id?1018230
- http://secunia.com/advisories/25640
- http://www.vupen.com/english/advisories/2007/2155
- http://osvdb.org/35341
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1643
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-035
- http://www.securityfocus.com/archive/1/471947/100/0/threaded