← All CVEs

CVE-2007-0675

high · 7.6

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

7.6
CVSS
17.7%
EPSS (exploit prob.)
97th
EPSS percentile
2007-02-03
Published

AV:N/AC:H/Au:N/C:C/I:C/A:C

Weaknesses

CWE-94

Affected products

VendorProductAffected versions
microsoftwindows_vistaall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2007-0675