CVE-2007-1211 is a denial-of-service vulnerability affecting Microsoft Windows 2000, XP, and Server 2003. It allows remote attackers to cause a system restart by tricking a user into opening a specially crafted Windows Metafile (WMF) image, which leads to an invalid memory dereference within kernel GDI functions. This vulnerability has a CVSS score of 7.1, indicating high severity due to its potential for complete system unavailability, though it requires user interaction. While there are no known active exploits in the wild or Metasploit modules, ExploitDB lists several related privilege escalation exploits for MS07-017, suggesting potential for similar attack vectors. Despite its age, the vulnerability has a high FAUCET Risk Score of 98/100, but it lacks significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:* | ||
goldCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:* | ||
goldCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:gold:*:itanium:*:*:*:*:* | ||
goldCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:* | ||
sp1CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.