9.3

CVE-2007-0942

Microsoft Internet Explorer 5.01 SP4 on Windows 2000 SP4; 6 SP1 on Windows 2000 SP4; 6 and 7 on Windows XP SP2, or Windows Server 2003 SP1 or SP2; and possibly 7 on Windows Vista does not properly "instantiate certain COM objects as ActiveX controls," which allows remote attackers to execute arbitrary code via a crafted COM object from chtskdic.dll.

Data is provided by the National Vulnerability Database (NVD)
MicrosoftIe Version6.0 Updatesp1
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version5.0.1 Updatesp4
   MicrosoftWindows 2000 Updatesp4
MicrosoftInternet Explorer Version6.0
   MicrosoftWindows 2003 Server Versionsp1
   MicrosoftWindows 2003 Server Versionsp1 Editionitanium
   MicrosoftWindows 2003 Server Versionsp1 Editionx64
   MicrosoftWindows 2003 Server Versionsp2
   MicrosoftWindows 2003 Server Versionsp2 Editionitanium
   MicrosoftWindows 2003 Server Versionsp2 Editionx64
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
MicrosoftInternet Explorer Version7.0
   MicrosoftWindows 2003 Server Versionsp1
   MicrosoftWindows 2003 Server Versionsp1 Editionitanium
   MicrosoftWindows 2003 Server Versionsp1 Editionx64
   MicrosoftWindows 2003 Server Versionsp2
   MicrosoftWindows 2003 Server Versionsp2 Editionitanium
   MicrosoftWindows 2003 Server Versionsp2 Editionx64
   MicrosoftWindows Vista
   MicrosoftWindows Vista Updategold Editionx64
   MicrosoftWindows Xp Updategold Editionprofessional_x64
   MicrosoftWindows Xp Updatesp2
   MicrosoftWindows Xp Updatesp2 Editionprofessional_x64
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 59.11% 0.982
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C