CVE-2007-0940
Summary
| CVE | CVE-2007-0940 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-05-08 23:19:00 UTC |
| Updated | 2018-10-16 16:35:00 UTC |
| Description | Unspecified vulnerability in the Cryptographic API Component Object Model Certificates ActiveX control (CAPICOM.dll) in Microsoft CAPICOM and BizTalk Server 2004 SP1 and SP2 allows remote attackers to execute arbitrary code via unspecified vectors, aka the "CAPICOM.Certificates Vulnerability." |
Risk And Classification
Problem Types: NVD-CWE-Other
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Microsoft | Biztalk Server | 2004 | sp1 | All | All |
| Application | Microsoft | Biztalk Server | 2004 | sp2 | All | All |
| Application | Microsoft | Biztalk Server | 2004 | sp1 | All | All |
| Application | Microsoft | Biztalk Server | 2004 | sp2 | All | All |
| Application | Microsoft | Capicom | All | All | All | All |
| Application | Microsoft | Capicom | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Microsoft Capicom ActiveX Control Remote Code Execution Vulnerability | BID | www.securityfocus.com | |
| IBM X-Force Exchange | XF | exchange.xforce.ibmcloud.com | |
| Microsoft CAPICOM 'CAPICOM.Certificates' ActiveX Control Lets Remote Users Execute Arbitrary Code - SecurityTracker | SECTRACK | www.securitytracker.com | |
| CAPICOM CAPICOM.Certificates ActiveX Control Vulnerability - Advisories - Secunia | SECUNIA | secunia.com | |
| Microsoft Security Bulletin MS07-028 - Critical | Microsoft Docs | MS | docs.microsoft.com | |
| SecurityFocus | HP | www.securityfocus.com | |
| SecurityTracker.com Archives - Microsoft BizTalk Server 'CAPICOM.Certificates' ActiveX Control Lets Remote Users Execute Arbitrary Code | SECTRACK | www.securitytracker.com | |
| 34397 | OSVDB | www.osvdb.org | |
| Repository / Oval Repository | OVAL | oval.cisecurity.org | |
| US-CERT Technical Cyber Security Alert TA07-128A -- Microsoft Updates for Multiple Vulnerabilities | CERT | www.us-cert.gov | US Government Resource |
| US-CERT Vulnerability Note VU#866305 | CERT-VN | www.kb.cert.org | US Government Resource |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | VUPEN | www.vupen.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.