Lucene search

K
cve[email protected]CVE-2007-0675
HistoryFeb 03, 2007 - 1:28 a.m.

CVE-2007-0675

2007-02-0301:28:00
CWE-94
web.nvd.nist.gov
27
sapi.dll
activex control
user-assisted
remote attackers
arbitrary files
web page
sound object

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.908 High

EPSS

Percentile

98.9%

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

Affected configurations

NVD
Node
microsoftwindows_vista32_bit

7.6 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:H/Au:N/C:C/I:C/A:C

6.6 Medium

AI Score

Confidence

Low

0.908 High

EPSS

Percentile

98.9%