CVE-2007-1347

Microsoft Windows Explorer - Denial of Service via Crafted Office File Document Summary

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2007-1347. PoCs published by Marsu.

AI-analyzed exploit summary This exploit targets a vulnerability in Microsoft Windows where a malformed .doc file causes a DoS by manipulating pointers in Ole32.dll, leading to a crash when the file is interacted with in Explorer. The PoC demonstrates arbitrary control over registers (EAX, EDX, ESI) via specific offsets in the file.

Description

Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remote attackers to cause a denial of service (memory corruption and crash) via an Office file with crafted document summary information, which causes an error in Ole32.dll.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Marsu · textdoswindows
https://www.exploit-db.com/exploits/3419

This exploit targets a vulnerability in Microsoft Windows where a malformed .doc file causes a DoS by manipulating pointers in Ole32.dll, leading to a crash when the file is interacted with in Explorer. The PoC demonstrates arbitrary control over registers (EAX, EDX, ESI) via specific offsets in the file.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Microsoft Windows (tested on Windows 2000 SP4 FR and XP SP2 FR)
No auth needed
Prerequisites: Victim interaction with a malformed .doc file in Explorer
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/36141
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/22847
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/3419
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1017736
Third Party Advisory, US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/194944

Scores

EPSS 0.2937
EPSS Percentile 97.9%

Details

CWE
CWE-119
Status published
Products (1)
microsoft/windows_explorer
Published Mar 08, 2007
Tracked Since Feb 18, 2026