{"api_version":"1","generated_at":"2026-07-23T09:29:44+00:00","cve":"CVE-2007-0041","urls":{"html":"https://cve.report/CVE-2007-0041","api":"https://cve.report/api/cve/CVE-2007-0041.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-0041","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-0041"},"summary":{"title":"CVE-2007-0041","description":"The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer\" and unvalidated message lengths, probably a buffer overflow.","state":"PUBLISHED","assigner":"microsoft","published_at":"2007-07-10 22:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-119","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"9.3","severity":"","vector":"AV:N/AC:M/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://osvdb.org/35954","name":"http://osvdb.org/35954","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-040 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24778","name":"http://www.securityfocus.com/bid/24778","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft .NET Framework PE Loader Remote Buffer Overflow Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-191A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018356","name":"http://www.securitytracker.com/id?1018356","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - .NET Buffer Overflows in PE Loader and JIT Compiler Let Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34637","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34637","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26003","name":"http://secunia.com/advisories/26003","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Microsoft .NET Framework Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html","name":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security bulletin] HPSBST02243 SSRT071446 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-036 to MS07-041","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2482","name":"http://www.vupen.com/english/advisories/2007/2482","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-0041","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-0041","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"41","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":".net_framework","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":".net_framework","cpe6":"1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"microsoft","cpe5":".net_framework","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2000","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_2003_server","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"41","vulnerable":"0","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_xp","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:03:37.003Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SSRT071446","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"MS07-040","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040"},{"name":"ADV-2007-2482","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2482"},{"name":"35954","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35954"},{"name":"26003","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26003"},{"name":"oval:org.mitre.oval:def:2093","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093"},{"name":"TA07-191A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"24778","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24778"},{"name":"ms-dotnet-pe-loader-bo(34637)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34637"},{"name":"1018356","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018356"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer\" and unvalidated message lengths, probably a buffer overflow."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"SSRT071446","tags":["vendor-advisory","x_refsource_HP"],"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"MS07-040","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040"},{"name":"ADV-2007-2482","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2482"},{"name":"35954","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35954"},{"name":"26003","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26003"},{"name":"oval:org.mitre.oval:def:2093","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093"},{"name":"TA07-191A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"24778","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24778"},{"name":"ms-dotnet-pe-loader-bo(34637)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34637"},{"name":"1018356","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018356"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2007-0041","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer\" and unvalidated message lengths, probably a buffer overflow."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"SSRT071446","refsource":"HP","url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"MS07-040","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-040"},{"name":"ADV-2007-2482","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2482"},{"name":"35954","refsource":"OSVDB","url":"http://osvdb.org/35954"},{"name":"26003","refsource":"SECUNIA","url":"http://secunia.com/advisories/26003"},{"name":"oval:org.mitre.oval:def:2093","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2093"},{"name":"TA07-191A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"24778","refsource":"BID","url":"http://www.securityfocus.com/bid/24778"},{"name":"ms-dotnet-pe-loader-bo(34637)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/34637"},{"name":"1018356","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018356"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2007-0041","datePublished":"2007-07-10T22:00:00.000Z","dateReserved":"2007-01-03T00:00:00.000Z","dateUpdated":"2024-08-07T12:03:37.003Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-10 22:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-119","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","baseScore":9.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2000:-:*:*:*:*:*:*:*","matchCriteriaId":"685F1981-EA61-4A00-89F8-A748A88962F8"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_2003_server:-:*:*:*:*:*:*:*","matchCriteriaId":"EAA86830-BEA8-4943-83EA-C267FA534223"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_vista:-:*:*:*:*:*:*:*","matchCriteriaId":"7CAEEA81-5037-4B68-98D9-83AAEBC98E20"},{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows_xp:-:*:*:*:*:*:*:*","matchCriteriaId":"B47EBFCC-1828-45AB-BC6D-FB980929A81A"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:1.0:*:*:*:*:*:*:*","matchCriteriaId":"766661C0-6A35-4F62-8325-3840A75CF3B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:1.1:*:*:*:*:*:*:*","matchCriteriaId":"1A927C9E-5CCC-4FC1-AE63-24B96A5FC51A"},{"vulnerable":true,"criteria":"cpe:2.3:a:microsoft:.net_framework:2.0:*:*:*:*:*:*:*","matchCriteriaId":"A419F50E-F32C-461C-95D0-978C5351FBAA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"41","Ordinal":"1","Title":"CVE-2007-0041","CVE":"CVE-2007-0041","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"41","Ordinal":"1","NoteData":"The PE Loader service in Microsoft .NET Framework 1.0, 1.1, and 2.0 for Windows 2000, XP, Server 2003, and Vista allows remote attackers to execute arbitrary code via unspecified vectors involving an \"unchecked buffer\" and unvalidated message lengths, probably a buffer overflow.","Type":"Description","Title":"CVE-2007-0041"},{"CveYear":"2007","CveId":"41","Ordinal":"2","NoteData":"2007-07-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"41","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}