{"api_version":"1","generated_at":"2026-07-23T03:12:50+00:00","cve":"CVE-2007-2240","urls":{"html":"https://cve.report/CVE-2007-2240","api":"https://cve.report/api/cve/CVE-2007-2240.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-2240","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-2240"},"summary":{"title":"CVE-2007-2240","description":"The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.","state":"PUBLISHED","assigner":"certcc","published_at":"2007-08-15 19:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36028","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36028","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kb.cert.org/vuls/id/570705","name":"http://www.kb.cert.org/vuls/id/570705","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"VU#570705 - IBM and Lenovo Access Support acpRunner ActiveX control fails to validate digital signatures","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26482","name":"http://secunia.com/advisories/26482","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM / Lenovo Access Support acpRunner ActiveX Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25311","name":"http://www.securityfocus.com/bid/25311","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Lenovo Inline Automated Solutions ActiveX Controls Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649","name":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Home - Global Support - US","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2882","name":"http://www.vupen.com/english/advisories/2007/2882","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-045 - Critical | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/39555","name":"http://osvdb.org/39555","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-2240","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-2240","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"2240","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lenovo","cpe5":"access_support","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"2240","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"lenovo","cpe5":"automated_solutions","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:33:27.473Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2007-2882","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2882"},{"name":"39555","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/39555"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649"},{"name":"MS07-045","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045"},{"name":"26482","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26482"},{"name":"ibm-lenovo-acprunner-code-execution(36028)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36028"},{"name":"25311","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25311"},{"name":"VU#570705","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/570705"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-14T00:00:00.000Z","descriptions":[{"lang":"en","value":"The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-12T19:57:01.000Z","orgId":"37e5125f-f79b-445b-8fad-9564f167944b","shortName":"certcc"},"references":[{"name":"ADV-2007-2882","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2882"},{"name":"39555","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/39555"},{"tags":["x_refsource_CONFIRM"],"url":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649"},{"name":"MS07-045","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045"},{"name":"26482","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26482"},{"name":"ibm-lenovo-acprunner-code-execution(36028)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36028"},{"name":"25311","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25311"},{"name":"VU#570705","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/570705"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cert@cert.org","ID":"CVE-2007-2240","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2007-2882","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2882"},{"name":"39555","refsource":"OSVDB","url":"http://osvdb.org/39555"},{"name":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649","refsource":"CONFIRM","url":"http://www-307.ibm.com/pc/support/site.wss/document.do?sitestyle=lenovo&lndocid=MIGR-67649"},{"name":"MS07-045","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-045"},{"name":"26482","refsource":"SECUNIA","url":"http://secunia.com/advisories/26482"},{"name":"ibm-lenovo-acprunner-code-execution(36028)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36028"},{"name":"25311","refsource":"BID","url":"http://www.securityfocus.com/bid/25311"},{"name":"VU#570705","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/570705"}]}}}},"cveMetadata":{"assignerOrgId":"37e5125f-f79b-445b-8fad-9564f167944b","assignerShortName":"certcc","cveId":"CVE-2007-2240","datePublished":"2007-08-15T19:00:00.000Z","dateReserved":"2007-04-25T00:00:00.000Z","dateUpdated":"2024-08-07T13:33:27.473Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-08-15 19:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:P","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:lenovo:access_support:*:*:*:*:*:*:*:*","matchCriteriaId":"22E333F5-25FB-4F86-9DB2-E32C5F7041A8"},{"vulnerable":true,"criteria":"cpe:2.3:h:lenovo:automated_solutions:1.0:*:*:*:*:*:*:*","matchCriteriaId":"53FE9F21-4C54-4F7A-9F15-45281A21EBB1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"2240","Ordinal":"1","Title":"CVE-2007-2240","CVE":"CVE-2007-2240","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"2240","Ordinal":"1","NoteData":"The IBM Lenovo Access Support acpRunner ActiveX control, as distributed in acpcontroller.dll before 1.2.8.0 and possibly acpir.dll before 1.0.0.9 (Automated Solutions 1.0 before fix pack 1), does not properly validate digital signatures of downloaded software, which makes it easier for remote attackers to spoof a download.","Type":"Description","Title":"CVE-2007-2240"},{"CveYear":"2007","CveId":"2240","Ordinal":"2","NoteData":"2007-08-15","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"2240","Ordinal":"3","NoteData":"2018-10-12","Type":"Other","Title":"Modified"}]}}}