Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-0675

Опубликовано: 03 фев. 2007
Источник: nvd
CVSS2: 7.6
EPSS Средний

Описание

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:o:microsoft:windows_vista:*:*:32_bit:*:*:*:*:*

EPSS

Процентиль: 97%
0.41573
Средний

7.6 High

CVSS2

Дефекты

CWE-94

Связанные уязвимости

github
почти 4 года назад

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

EPSS

Процентиль: 97%
0.41573
Средний

7.6 High

CVSS2

Дефекты

CWE-94