Format String Vulnerability in IBM Lenovo Access Support ActiveX Control
CVE-2007-2928
Currently unrated
Key Information:
- Vendor
- Lenovo
- Vendor
- CVE Published:
- 15 August 2007
Summary
The IBM Lenovo Access Support ActiveX control is vulnerable to a format string issue that allows remote attackers to execute arbitrary code. This vulnerability arises due to improper handling of format string specifiers in certain data inputs, potentially affecting various system configurations. Users are advised to apply relevant patches to mitigate any risks associated with this vulnerability. The affected versions include acpcontroller.dll prior to 1.2.8.0 and acpir.dll before 1.0.0.9, among others.
References
EPSS Score
5% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved