Microsoft XML Core Services substringData() Integer Overflow

Strike ID:
E07-1pr01
CVSS:
9.3 (AV:N/AC:M/Au:N/C:C/I:C/A:C)
False Positive:
f
Variants:
1
Year:
2007

Description

This strike exploits an integer overflow vulnerability in the Microsoft XML Core Services control. This flaw is a combination of improper input validation in the XML software (MS07-042) and an integer overflow in the OLE Automation Library (MS07-043).

CVE

Bid