Lucene search

K
cve[email protected]CVE-2007-3040
HistorySep 12, 2007 - 1:17 a.m.

CVE-2007-3040

2007-09-1201:17:00
CWE-119
web.nvd.nist.gov
33
4
cve-2007-3040
buffer overflow
agentdpv.dll
microsoft agent
windows 2000
remote code execution
activex control
security vulnerability

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%

Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.

Affected configurations

NVD
Node
microsoftwindows_2000sp4

Social References

More

9.3 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:M/Au:N/C:C/I:C/A:C

7.6 High

AI Score

Confidence

Low

0.941 High

EPSS

Percentile

99.2%