CVE Database
/

CVE-2007-2216

Back to search

CVE-2007-2216

Published: Aug 14, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

The tblinf32.dll (aka vstlbinf.dll) ActiveX control for Internet Explorer 5.01, 6 SP1, and 7 uses an incorrect IObjectsafety implementation, which allows remote attackers to execute arbitrary code by requesting the HelpString property, involving a crafted DLL file argument to the TypeLibInfoFromFile function, which overwrites the HelpStringDll property to call the DLLGetDocumentation function in another DLL file, aka "ActiveX Object Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

36396
vdb-entry
x_refsource_OSVDB
MS07-045
vendor-advisory
x_refsource_MS
TA07-226A
third-party-advisory
x_refsource_CERT
oval:org.mitre.oval:def:2109
vdb-entry
signature
x_refsource_OVAL
ADV-2007-2869
vdb-entry
x_refsource_VUPEN
26419
third-party-advisory
x_refsource_SECUNIA
25289
vdb-entry
x_refsource_BID
1018562
vdb-entry
x_refsource_SECTRACK
20070815 TlbInf32 ActiveX Command Execution
mailing-list
x_refsource_BUGTRAQ

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now