Groove
Vendor:
First CVE: Jul 7, 2008 · Active for 18 years
5
Total CVEs
More Total CVEs than 77% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 36% of tracked products
20.0%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Groove over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 7, 2008
18 years ago
Most Recent CVE
Jun 13, 2012
5,154 days ago
CVE Severity & Scoring
Groove5 CVEs
40%
60%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network1 (20.0%)
Unknown4 (80.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (20.0%)
High0 (0.0%)
Unknown4 (80.0%)
User Interaction
None0 (0.0%)
Unknown4 (80.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None1 (20.0%)
Unknown4 (80.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-1889HIGH Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attackers to execute arbitrary code or cause a denial of service (me | Jun 13, 2012 | 8.8 | 97 | YES | YES |
CVE-2011-1892MEDIUM Microsoft Office Groove 2007 SP2, SharePoint Workspace 2010 Gold and SP1, Office Forms Server 2007 SP2, Office SharePoint Server 2007 SP2, Office SharePoint Server 2010 Gold and SP | Sep 15, 2011 | 4.0 | 44 | NO | YES |
CVE-2010-3146HIGH Multiple untrusted search path vulnerabilities in Microsoft Groove 2007 SP2 allow local users to gain privileges via a Trojan horse (1) mso.dll or (2) GroovePerfmon.dll file in the | Aug 27, 2010 | 9.3 | 44 | NO | YES |
CVE-2008-4033MEDIUM Cross-domain vulnerability in Microsoft XML Core Services 3.0 through 6.0, as used in Microsoft Expression Web, Office, Internet Explorer, and other products, allows remote attacke | Nov 12, 2008 | 4.3 | 33 | NO | YES |
CVE-2008-3068HIGH Microsoft Crypto API 5.131.2600.2180 through 6.0, as used in Outlook, Windows Live Mail, and Office 2007, performs Certificate Revocation List (CRL) checks by using an arbitrary UR | Jul 7, 2008 | 7.5 | 28 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
1 CVE
20.0% of CVEs· 98th percentile
Metasploit
1 CVE
20.0% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
4 CVEs
80.0% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Groove
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2007 | 3 | 6.9 | 23.2% | 0 | 2 |