CVE-2007-0940Microsoft Biztalk Server vulnerability

5 documents4 sources
Severity
9.3CRITICALNVD
EPSS
75.2%
top 1.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 8
Latest updateMay 1

Description

Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-wgrj-2whc-pfpg: Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM2022-05-01
CVEList
CVE-2007-0940: Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM2007-05-08

💬Community

2
Bugzilla
CVE-2007-4574 EM64T local DoS2007-09-20
Bugzilla
CVE-2007-3513 Locally triggerable memory consumption in usblcd2007-07-11
CVE-2007-0940 — Microsoft Biztalk Server vulnerability | cvebase