peter bassill · operator
$ cve CVE-2007-3168 JSON

CVE-2007-3168 EXPLOIT

7.8
HIGH · CVSS 2.0 · EPSS 6.3% (pctl 93)

Patch early

A public exploit exists.

Description

A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.

Scoring

CVSS7.8 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:C
EPSS6.31% — more likely to be exploited than 93% of all CVEs
On CISA KEVno
Public exploityes
Published2007-06-11
Last modified2026-06-16

Affected (1)

VendorProduct
edrawoffice viewer component

Public exploits

SourceTitleDate
exploit-dbEDraw Office Viewer Component - Unsafe Method2007-05-30

References

→ the Explorer  ·  watch your stack  ·  NVD