vendor:
Microsoft Windows
by:
Not mentioned
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Microsoft Windows
Affected Version From: Microsoft Windows XP SP2
Affected Version To: Not mentioned
Patch Exists: YES
Related CWE: CVE-2007-3039
CPE: o:microsoft:windows_xp::sp2
Platforms Tested: Windows
2007
Buffer Overflow Vulnerability in CFileFind::FindFile Method
The CFileFind::FindFile method in the MFC library for Microsoft Windows is prone to a buffer-overflow vulnerability because the method fails to perform adequate boundary checks of user-supplied input. Successfully exploiting this issue may allow attackers to execute arbitrary code in the context of applications that use the vulnerable method.
Mitigation:
Apply the latest security patches from Microsoft to fix the vulnerability. Avoid using or exposing the vulnerable method in applications.