Lucene search

K
cve[email protected]CVE-2007-2221
HistoryMay 08, 2007 - 11:19 p.m.

CVE-2007-2221

2007-05-0823:19:00
web.nvd.nist.gov
122
cve-2007-2221
vulnerability
mdsauth.dll
com object
microsoft
windows media server
internet explorer
remote attackers
arbitrary files
arbitrary file rewrite
nvd

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.936 High

EPSS

Percentile

99.1%

Unspecified vulnerability in the mdsauth.dll COM object in Microsoft Windows Media Server in the Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; or 7 on Windows Vista allows remote attackers to overwrite arbitrary files via unspecified vectors, aka the “Arbitrary File Rewrite Vulnerability.”

Affected configurations

NVD
Node
microsoftwindows_2000sp4
AND
microsoftinternet_explorerMatch5.01sp4
Node
microsoftwindows_2000sp4
AND
microsoftinternet_explorerMatch6sp1
Node
microsoftwindows_xpsp2
AND
microsoftinternet_explorerMatch6.0
OR
microsoftinternet_explorerMatch7.0
Node
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_2003_serverMatchsp2
AND
microsoftinternet_explorerMatch6.0
OR
microsoftinternet_explorerMatch7.0
Node
microsoftwindows_vista
AND
microsoftinternet_explorerMatch7.0

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

6.5 Medium

AI Score

Confidence

Low

0.936 High

EPSS

Percentile

99.1%