PoC Index

CVE-2007-2222

HIGH 9.3EPSS 54.7%

Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.

CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
54.74% chance of exploitation in the next 30 days, 99th percentile
Published
2007-06-12
Updated
2024-08-07

Proof-of-concept exploits (1)

ExploitDB entries (2)

References

Related