CVE-2007-3168

EDraw Office Viewer <5.0 - RCE

Title source: llm

Description

A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.

Exploits (1)

exploitdb WORKING POC VERIFIED
by shinnai · htmlremotewindows
https://www.exploit-db.com/exploits/4010

Scores

EPSS 0.1245
EPSS Percentile 93.9%

Details

Status published
Products (2)
edraw/office_viewer_component 4.0.5.20
edraw/office_viewer_component < 5.0
Published Jun 11, 2007
Tracked Since Feb 18, 2026