CVE-2007-2987 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 32.7% (pctl 98)
Patch early
A public exploit exists.
Description
Multiple buffer overflows in certain ActiveX controls in sasatl.dll in Zenturi ProgramChecker allow remote attackers to execute arbitrary code via unspecified vectors, possibly involving the (1) DebugMsgLog or (2) DoFileProperties methods.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 32.7% — more likely to be exploited than 98% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2007-06-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| zenturi | zenturi programchecker |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Zenturi ProgramChecker - ActiveX Control Arbitrary File Download (Metasploit) | 2010-11-24 |
| exploit-db | Zenturi NixonMyPrograms Class 'sasatl.dll 1.5.0.531' - Remote Buffer Overflow | 2007-07-23 |
| exploit-db | Zenturi ProgramChecker - ActiveX 'sasatl.dll' Remote Buffer Overflow | 2007-06-01 |
References
- http://osvdb.org/36715
- http://secunia.com/advisories/25473
- http://www.kb.cert.org/vuls/id/603529
- http://www.securityfocus.com/bid/24217
- http://www.securityfocus.com/bid/24274
- http://www.vupen.com/english/advisories/2007/1977
- http://osvdb.org/36715
- http://secunia.com/advisories/25473
- http://www.kb.cert.org/vuls/id/603529
- http://www.securityfocus.com/bid/24217
- http://www.securityfocus.com/bid/24274
- http://www.vupen.com/english/advisories/2007/1977
→ the Explorer · watch your stack · NVD