Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4jq3-gmvg-2rgg

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

EPSS

Процентиль: 97%
0.41573
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
около 19 лет назад

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

EPSS

Процентиль: 97%
0.41573
Средний

Дефекты

CWE-94