VDB
CVE-2007-3040
CVE-2007-3040
PUBLISHED
CVSS 9.300000190734863 CRITICAL
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
EPSS 59.17% · 98.3th percentile
Risk Scores
CVSS 2.0
9.300000190734863
EPSS Score
59.17%
98.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| microsoft | windows_2000 | |
| n/a | n/a | n/a |
Timeline
- Sep 12, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 22, 2023 EPSS Score
- Apr 27, 2023 EPSS Score
- Jun 2, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 30, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
References
- 36934 vdb
- 20070911 Microsoft Windows 2000 Agent URL Canonicalizing Stack Based Buffer Overflow Vulnerability third-party-advisory
- 25566 vdb
- 3124 third-party-advisory
- MS07-051 vendor-advisory
- ms-agent-url-code-execution(35752) vdb
- oval:org.mitre.oval:def:2116 vdb
- 26753 third-party-advisory
- TA07-254A third-party-advisory
- 1018677 vdb
- ADV-2007-3113 vdb
- VU#716872 third-party-advisory
- 20070911 Assurent VR - Microsoft Agent Crafted URL Stack Buffer Overflow mailing-list
- https://nvd.nist.gov/vuln/detail/CVE-2007-3040 advisory