CVE-2007-2216 describes a critical remote code execution vulnerability in the tblinf32.dll ActiveX control affecting Microsoft Internet Explorer versions 5.01, 6 SP1, and 7. The flaw stems from an incorrect IObjectSafety implementation, allowing attackers to execute arbitrary code by manipulating the HelpString property with a crafted DLL file. This vulnerability carries a CVSS score of 9.3, indicating a severe risk with network-based attacks, medium complexity, and complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and lacking widespread community discussion or media coverage, an exploit is publicly available on ExploitDB, demonstrating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.01CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:5.01:*:*:*:*:*:*:* | ||
6CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:6:sp1:*:*:*:*:*:* | ||
7CPE matchmatch criteria | cpe:2.3:a:microsoft:internet_explorer:7:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.