peter bassill · operator
$ cve CVE-2007-2223 JSON

CVE-2007-2223 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 48.7% (pctl 99)

Patch early

A public exploit exists.

Description

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS48.72% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-08-14
Last modified2026-06-16

Affected (11)

VendorProduct
microsoftexpression web
microsoftoffice
microsoftoffice compatibility pack
microsoftoffice groove server
microsoftoffice sharepoint server
microsoftwindows server 2003
microsoftwindows server 2008
microsoftwindows vista
microsoftwindows xp
microsoftword viewer
microsoftxml core services

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD