>> Microsoft Windows Vector Markup Language Code Execution Issue (MS07-050)
Title : Microsoft Windows Vector Markup Language Code Execution Issue (MS07-050) VUPEN ID : VUPEN/ADV-2007-2874 CVE ID : CVE-2007-1749
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-08-14
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an integer underflow error in the "CDownloadSink::OnDataAvailable()" function within the vector graphics link library (vgx.dll) when interacting with Internet Explorer, which could be exploited by remote attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.