« Volver al listado

CVE-2007-2923

Estado: ModificadaAlta (9.3)—

El método launch en el controlador ActiveX LocalExec (LocalExec.ocx) en Novell exteNd Director 4.1 y Portal Services permite a atacantes remotos ejecutar comandos de su elección.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-2923",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 9.3,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ]
  },
  "affected": [
    {
      "source": "cret@cert.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-06-18T10:30:00.000",
  "references": [
    {
      "url": "http://osvdb.org/37318",
      "source": "cret@cert.org"
    },
    {
      "url": "http://secunia.com/advisories/25710",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/793433",
      "tags": [
        "US Government Resource"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.novell.com/documentation/nedse41/readmesp2.txt",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/24493",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.securitytracker.com/id?1018258",
      "source": "cret@cert.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2235",
      "source": "cret@cert.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34898",
      "source": "cret@cert.org"
    },
    {
      "url": "https://secure-support.novell.com/KanisaPlatform/Publishing/360/3169416_f.SAL_Public.html",
      "source": "cret@cert.org"
    },
    {
      "url": "http://osvdb.org/37318",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/25710",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.kb.cert.org/vuls/id/793433",
      "tags": [
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.novell.com/documentation/nedse41/readmesp2.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/24493",
      "tags": [
        "Exploit",
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securitytracker.com/id?1018258",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/2235",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/34898",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://secure-support.novell.com/KanisaPlatform/Publishing/360/3169416_f.SAL_Public.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The launch method in the LocalExec ActiveX control (LocalExec.ocx) in Novell exteNd Director 4.1 and Portal Services allows remote attackers to execute arbitrary commands."
    },
    {
      "lang": "es",
      "value": "El método launch en el controlador ActiveX LocalExec (LocalExec.ocx) en Novell exteNd Director 4.1 y Portal Services permite a atacantes remotos ejecutar comandos de su elección."
    }
  ],
  "lastModified": "2026-06-16T22:40:42.427",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:novell:extend_director:4.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "851D826B-5414-4F11-8E35-BB83B522685D"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cret@cert.org"
}