Lucene search

K
cve[email protected]CVE-2007-0940
HistoryMay 08, 2007 - 11:19 p.m.

CVE-2007-0940

2007-05-0823:19:00
web.nvd.nist.gov
35
vulnerability
cryptographic api
capicom
certificates
activex control
microsoft
biztalk server
remote code execution
cve-2007-0940

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.94 High

EPSS

Percentile

99.2%

Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the “CAPICOM.Certificates Vulnerability.”

Affected configurations

NVD
Node
microsoftbiztalk_serverMatch2004sp1
OR
microsoftbiztalk_serverMatch2004sp2
OR
microsoftcapicom

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.5 High

AI Score

Confidence

Low

0.94 High

EPSS

Percentile

99.2%