CVE-2007-2222 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 54.7% (pctl 99)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in the (1) ActiveListen (Xlisten.dll) and (2) ActiveVoice (Xvoice.dll) speech controls, as used by Microsoft Internet Explorer 5.01, 6, and 7, allow remote attackers to execute arbitrary code via a crafted ActiveX object that triggers memory corruption, as demonstrated via the ModeName parameter to the FindEngine function in ACTIVEVOICEPROJECTLib.DirectSS.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 54.74% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-06-12 |
| Last modified | 2026-06-16 |
Affected (5)
| Vendor | Product |
|---|---|
| microsoft | internet explorer |
| microsoft | windows 2000 |
| microsoft | windows 2003 server |
| microsoft | windows vista |
| microsoft | windows xp |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Microsoft Speech API ActiveX Control (Windows 2000 SP4) - Remote Buffer Overflow (MS07-033) | 2007-06-13 |
| exploit-db | Microsoft Speech API ActiveX Control (Windows XP SP2) - Remote Buffer Overflow (MS07-033) | 2007-06-13 |
References
- http://osvdb.org/35353
- http://retrogod.altervista.org/win_speech_2k_sp4.html
- http://retrogod.altervista.org/win_speech_xp_sp2.html
- http://secunia.com/advisories/25627
- http://securitytracker.com/id?1018235
- http://www.exploit-db.com/exploits/4065
- http://www.kb.cert.org/vuls/id/507433
- http://www.securityfocus.com/archive/1/471947/100/0/threaded
- http://www.securityfocus.com/bid/24426
- http://www.us-cert.gov/cas/techalerts/TA07-163A.html
- http://www.vupen.com/english/advisories/2007/2153
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-033
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34630
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2031
- http://osvdb.org/35353
- http://retrogod.altervista.org/win_speech_2k_sp4.html
- http://retrogod.altervista.org/win_speech_xp_sp2.html
- http://secunia.com/advisories/25627
- http://securitytracker.com/id?1018235
- http://www.exploit-db.com/exploits/4065
→ the Explorer · watch your stack · NVD