peter bassill · operator
$ cve CVE-2007-2216 JSON

CVE-2007-2216 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 41.4% (pctl 99)

Patch early

A public exploit exists.

Description

The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS41.39% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-16
On CISA KEVno
Public exploityes
Published2007-08-14
Last modified2026-06-16

Affected (1)

VendorProduct
microsoftinternet explorer

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD