CVE-2007-4891
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) StartProcess, (2) SyncShell, (3) SaveAs, (4) CABDefaultURL, (5) CABFileName, and (6) CABRunFile methods, which allows remote attackers to execute arbitrary programs and have other impacts, as demonstrated using absolute pathnames in arguments to StartProcess and SyncShell.
- Affected products
- Visual Studio
- Microsoft Visual Studio
- = 6.0, 6.0.0.9782
- CVSS 2.0
- 6.8 MEDIUM
- EPSS
- 31.0% (98th percentile)
- Weakness
- CWE-78
- NVD status
- Modified
- Published
- 2007-09-14
CVE-2007-4891 at NVD
6 known exploits for CVE-2007-4891
Proof-of-concept code and exploit modules indexed by Sploitus
Microsoft Visual Studio PDWizard.ocx ActiveX vulnerability
Microsoft Visual Studio PDWizard.ocx ActiveX vulnerability
Microsoft Visual Studio PDWizard.ocx ActiveX vulnerability
Microsoft Visual Studio PDWizard.ocx ActiveX vulnerability
DSquare Exploit Pack: D2SEC_PDWIZARD
Microsoft Visual Studio 6.0 - 'PDWizard.ocx' Remote Command Execution