Vulnerability Note VU#866305
Microsoft Cryptographic API Component Object Model Certificates ActiveX control contains a remote code execution vulnerability
Overview
Microsoft Cryptographic API Component Object Model (CAPICOM) Certificates ActiveX control contains a vulnerability that may allow a remote, unauthenticated attacker to execute arbitrary code.
Description
The Microsoft Cryptographic API Component Object Model (CAPICOM) Certificates ActiveX control provides a method of encrypting data using Windows CryptoAPI functionality. A vulnerability exists in the way that the CAPICOM.Certificates control validates input. By convincing a user to visit a malicious web site, an attacker may be able to execute arbitrary code. |
Impact
A remote, unauthenticated attacker may be able to gain control of the system, execute arbitrary code, or access the system with escalated privileges. |
Solution
Apply an Update Microsoft has released updates in Microsoft Security Bulletin MS07-028 to address this issue. |
Workarounds
{FBAB033B-CDD0-4C5E-81AB-AEA575CD1338} Microsoft has releases several additional workarounds to mitigate this issue. Please see Microsoft Security Bulletin MS07-028 for further details. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 08 May 2007 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/bulletin/ms07-028.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS07-045.mspx
- http://secunia.com/advisories/25185/
Credit
This vulnerability was reported in Microsoft Security Bulletin MS07-028. Microsoft credits Chris Ries of VigilantMinds Inc. for reporting the vulnerability to them.
This document was written by Katie Steiner.
Other Information
- CVE IDs: CVE-2007-0940
- Date Public: 08 May 2007
- Date First Published: 08 May 2007
- Date Last Updated: 14 Aug 2007
- Severity Metric: 3.09
- Document Revision: 17
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.