Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.102059
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows Vector Markup Language Buffer Overflow (938127)
Summary:This security update resolves a privately reported vulnerability in the; Vector Markup Language (VML) implementation in Windows. The; vulnerability could allow remote code execution if a user viewed a; specially crafted Web page using Internet Explorer.;; Users whose accounts are configured to have fewer user rights on; the system could be less impacted than users who operate with; administrative user rights.
Description:Summary:
This security update resolves a privately reported vulnerability in the
Vector Markup Language (VML) implementation in Windows. The
vulnerability could allow remote code execution if a user viewed a
specially crafted Web page using Internet Explorer.

Users whose accounts are configured to have fewer user rights on
the system could be less impacted than users who operate with
administrative user rights.

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2007-1749
BugTraq ID: 25310
http://www.securityfocus.com/bid/25310
Bugtraq: 20070814 EEYE: VGX.DLL Compressed Content Heap Overflow Vulnerability (Google Search)
http://www.securityfocus.com/archive/1/476498/100/0/threaded
Cert/CC Advisory: TA07-226A
http://www.us-cert.gov/cas/techalerts/TA07-226A.html
CERT/CC vulnerability note: VU#468800
http://www.kb.cert.org/vuls/id/468800
http://research.eeye.com/html/advisories/published/AD20070814a.html
Microsoft Security Bulletin: MS07-050
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-050
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1784
http://www.securitytracker.com/id?1018568
http://secunia.com/advisories/26409
http://securityreason.com/securityalert/3020
http://www.vupen.com/english/advisories/2007/2874
CopyrightCopyright (C) 2010 LSS

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.