cbcvebase.
CVE-2007-0041
published 2007-07-10

CVE-2007-0041: The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary…

PriorityP354critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
30.67%
98.0th percentile
The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an "unchecked buffer" and unvalidated message lengths, probably a buffer overflow.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftnet_framework
microsoftnet_framework
microsoftnet_framework

Detection & IOCsextracted from sources · hover to see the quote

  • CVE-2007-0041 was patched in Microsoft Security Bulletin MS07-040; detection/patching context is the .NET Framework PE Loader service handling unvalidated message lengths (buffer overflow) in Microsoft .NET Framework 1.0, 1.1, and 2.0.
  • ·The vulnerability involves an 'unchecked buffer' and unvalidated message lengths in the PE Loader service; the attack vector and specific payload format are unspecified in public disclosures, limiting precise signature development.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.