Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-1205 | First vendor Publication | 2007-04-10 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:M/Au:N/C:C/I:C/A:C) | |||
---|---|---|---|
Cvss Base Score | 9.3 | Attack Range | Network |
Cvss Impact Score | 10 | Attack Complexity | Medium |
Cvss Expoit Score | 8.6 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-1205 |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:2034 | |||
Oval ID: | oval:org.mitre.oval:def:2034 | ||
Title: | Microsoft Agent URL Parsing Vulnerability | ||
Description: | Unspecified vulnerability in Microsoft Agent (msagent\agentsvr.exe) in Windows 2000 SP4, XP SP2, and Server 2003, 2003 SP1, and 2003 SP2 allows remote attackers to execute arbitrary code via crafted URLs, which result in memory corruption. | ||
Family: | windows | Class: | vulnerability |
Reference(s): | CVE-2007-1205 | Version: | 6 |
Platform(s): | Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003 | Product(s): | |
Definition Synopsis: | |||
|
CPE : Common Platform Enumeration
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
34009 | Microsoft Windows Agent URL Parsing Memory Corruption |
Information Assurance Vulnerability Management (IAVM)
Date | Description |
---|---|
2007-04-12 | IAVM : 2007-A-0021 - Microsoft Agent URL Parsing Remote Code Execution Vulnerability Severity : Category II - VMSKEY : V0013934 |
Snort® IPS/IDS
Date | Description |
---|---|
2014-01-10 | Microsoft Agent v1.5 ActiveX function call access RuleID : 8856 - Revision : 12 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent v1.5 ActiveX clsid unicode access RuleID : 8855 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Agent v2.0 ActiveX function call access RuleID : 8854 - Revision : 14 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent v2.0 ActiveX clsid unicode access RuleID : 8853 - Revision : 8 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Agent v2.0 ActiveX clsid access RuleID : 8852 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent Custom Proxy Class ActiveX clsid unicode access RuleID : 8851 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Agent Custom Proxy Class ActiveX clsid access RuleID : 8850 - Revision : 13 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid unicode access RuleID : 8849 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Agent Notify Sink Custom Proxy Class ActiveX clsid access RuleID : 8848 - Revision : 13 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent Character Custom Proxy Class ActiveX clsid unicode access RuleID : 8847 - Revision : 7 - Type : WEB-ACTIVEX |
2014-01-10 | Microsoft Agent Character Custom Proxy Class ActiveX clsid access RuleID : 8846 - Revision : 13 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows Agent v1.5 ActiveX clsid access RuleID : 4172 - Revision : 15 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Windows Agent Control ActiveX clsid access RuleID : 12448 - Revision : 19 - Type : BROWSER-PLUGINS |
2014-01-10 | Microsoft Agent v1.5 ActiveX function call unicode access RuleID : 10465 - Revision : 7 - Type : WEB-ACTIVEX |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-04-10 | Name : Arbitrary code can be executed on the remote host through the web or email cl... File : smb_nt_ms07-020.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:17:45 |
|
2024-11-28 12:11:40 |
|
2021-05-04 12:05:27 |
|
2021-04-22 01:06:00 |
|
2020-05-23 00:19:22 |
|
2018-10-16 21:19:51 |
|
2018-10-13 00:22:36 |
|
2017-10-11 09:23:52 |
|
2016-04-26 15:49:29 |
|
2014-02-17 10:39:17 |
|
2014-01-19 21:23:56 |
|
2013-11-11 12:37:41 |
|
2013-05-11 10:20:01 |
|