CVE-2007-0069 describes an unspecified vulnerability in the kernel of Microsoft Windows XP SP2, Server 2003, and Vista. This flaw allows remote attackers to trigger a denial of service (CPU consumption) and potentially execute arbitrary code by sending specially crafted IGMPv3 and MLDv2 packets that lead to memory corruption. The vulnerability carries a critical CVSS score of 9.3, indicating a high-severity risk. It can be exploited remotely with medium attack complexity, potentially leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity, there is no evidence of active exploitation (KEV: No), nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. Community discussion and media coverage for this CVE are also extremely low, suggesting it has not garnered significant attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.