Back to Database
Status published
High
CVE-2007-3168
A certain ActiveX control in the EDraw Office Viewer Component...
Vulnerability Description
A certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and other versions before 5.0, allows remote attackers to delete arbitrary files via the DeleteLocalFile method.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-3168
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vupen.com/english/advisories/2007/1992
- http://www.ocxt.com/archives/28
- http://www.securityfocus.com/bid/24230
- http://shinnai.altervista.org/viewtopic.php?id=42&t_id=31
- https://www.exploit-db.com/exploits/4010
- http://secunia.com/advisories/25418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/34588
- http://moaxb.blogspot.com/2007/05/moaxb-28-edraw-office-viewer-component.html
- http://osvdb.org/36044
More from edraw
View All →CVE-2009-2169
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in...
Critical
9.3
CVE-2007-5826
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control...
Critical
9.3
CVE-2007-5257
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx...
Critical
10
CVE-2007-4821
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1...
Critical
9.3
CVE-2007-4420
Absolute path traversal vulnerability in a certain ActiveX control in...
Critical
9.3
Affected Vendor
edraw
View all reports →Affected Software
office viewer component
Vulnerable Versions:
0, 4.0.5.20
Timeline
Official Publish:
June 11th, 2007
Last Modified:
August 7th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.