Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2007-0675

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.395
EPSS Ranking 97.2%
CVSS Severity
CVSS v2 Score 7.6
References
Products affected by CVE-2007-0675


Contact Us

Shodan ® - All rights reserved