CVE-2007-2223
Microsoft XML Core Services 3.0-6.0 - Remote Code Execution via substringData Integer Overflow
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-2223. PoCs published by anonymous.
AI-analyzed exploit summary The code is a stub for CVE-2007-2223, demonstrating an integer overflow vulnerability in Microsoft XML Core Services. It includes commented-out JavaScript that would trigger the vulnerability but lacks a functional exploit.
Description
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
Exploits (1)
The code is a stub for CVE-2007-2223, demonstrating an integer overflow vulnerability in Microsoft XML Core Services. It includes commented-out JavaScript that would trigger the vulnerability but lacks a functional exploit.