Format String Vulnerability in IBM Lenovo Access Support ActiveX Control
CVE-2007-2928

Currently unrated

Key Information:

Vendor
Lenovo
Vendor
CVE Published:
15 August 2007

Summary

The IBM Lenovo Access Support ActiveX control is vulnerable to a format string issue that allows remote attackers to execute arbitrary code. This vulnerability arises due to improper handling of format string specifiers in certain data inputs, potentially affecting various system configurations. Users are advised to apply relevant patches to mitigate any risks associated with this vulnerability. The affected versions include acpcontroller.dll prior to 1.2.8.0 and acpir.dll before 1.0.0.9, among others.

References

EPSS Score

5% chance of being exploited in the next 30 days.

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.