HIGH · 9.3

CVE-2007-2223

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overf...

Vulnerability Description

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
MicrosoftXml Core Services3.0
MicrosoftWindows Server 2003All versions
MicrosoftWindows Vista-
MicrosoftWindows Xp-
MicrosoftWindows Server 2008-
MicrosoftExpression WebAll versions
MicrosoftOffice2003
MicrosoftOffice Compatibility Pack2007
MicrosoftOffice Groove Server2007
MicrosoftOffice Sharepoint ServerAll versions
MicrosoftWord Viewer2003

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-2223?

CVE-2007-2223 is a vulnerability with a CVSS score of 9.3 (HIGH). Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overf...

How severe is CVE-2007-2223?

CVE-2007-2223 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-2223?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Xml Core Services, Microsoft Windows Server 2003, Microsoft Windows Vista, Microsoft Windows Xp, Microsoft Windows Server 2008.