← Vulnerability feed

Vulnerability record · CVE-2007-2223 · published 14 August 2007

CVE-2007-2223: Microsoft XML Core Services substringData integer overflow RCE

Microsoft · Xml Core Services

MSXML 3.0 through 6.0 contains an integer overflow in the substringData method on TextNode and XMLDOM objects that leads to a buffer overflow. A remote attacker can trigger it to run arbitrary code in the context of the affected process, making it a serious code execution flaw in a widely deployed XML parser.

9.3 CVSS 2.0 High EPSS 49% · top 1.2% CWE-119 · Memory buffer overflowCWE-190 · Integer overflow
9.3CVSS 2.0 base score
49%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityRemote unauthenticated code execution with complete impact and a very high EPSS percentile, though no KEV listing or confirmed in-the-wild exploitation is recorded.

What it is

MSXML 3.0 through 6.0 contains an integer overflow in the substringData method on TextNode and XMLDOM objects that leads to a buffer overflow. A remote attacker can trigger it to run arbitrary code in the context of the affected process, making it a serious code execution flaw in a widely deployed XML parser.

Impact

Successful exploitation lets a remote attacker execute arbitrary code with the privileges of the application using MSXML, potentially leading to full system compromise. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.

Attack surface

Reachable over the network (AV:N) with no authentication required (Au:N), but the CVSS vector notes medium access complexity (AC:M), implying some precondition such as a crafted document being parsed or a user being induced to open it. No user interaction detail is given beyond the vector.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.487 (98.8th percentile), indicating elevated predicted exploitation likelihood. References are advisories and a vendor patch bulletin, with no public exploit tag supplied.

What to do

  • Apply the Microsoft security bulletin MS07-042 patch for MSXML immediately.
  • Inventory systems and applications that load MSXML 3.0 through 6.0, including legacy Office and browser-dependent components.
  • Restrict processing of untrusted XML documents and disable or block risky MSXML object instantiation where feasible.
  • Where patching is not possible, isolate affected hosts and limit outbound and lateral network access.

Detection

  • Monitor for crashes or abnormal process termination in applications that parse XML, especially those loading msxml3.dll through msxml6.dll.
  • Hunt for suspicious child processes spawned by Office, browser or script host processes that use MSXML.
  • Review endpoint logs for exploitation artifacts around XML parsing and unusual memory corruption indicators.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576 Broken Link
http://secunia.com/advisories/26447 Vendor Advisory
http://www.kb.cert.org/vuls/id/361968 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/476527/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/476747/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/25301 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018559 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/2866 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-048/ Third Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2069 Third Party Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=576 Broken Link
http://secunia.com/advisories/26447 Vendor Advisory
http://www.kb.cert.org/vuls/id/361968 Third Party AdvisoryUS Government Resource
http://www.securityfocus.com/archive/1/476527/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/476747/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/25301 Third Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1018559 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2007/2866 Vendor Advisory
http://www.zerodayinitiative.com/advisories/ZDI-07-048/ Third Party AdvisoryVDB Entry
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-042 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2069 Third Party Advisory

Track CVE-2007-2223 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2012-1889Microsoft XML Core Services memory corruption via crafted websiteMicrosoft XML Core Services versions 3.0 through 6.0 access uninitialized memory, leading to memory corruption. A remote attacker can trigger this th…KEVEPSS 84%analysed6.5CVE-2017-0022Microsoft XML Core Services memory handling allows file existence disclosureMSXML in multiple Windows versions improperly handles objects in memory, letting a crafted web site probe for files on the local disk. The flaw is an…KEVEPSS 18%analysed9.3CVE-2013-0007Microsoft xml core services code injection vulnerabilityMicrosoft XML Core Services (aka MSXML) 4.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…EPSS 32%9.3CVE-2010-2561Microsoft xml core services code injection vulnerabilityMicrosoft XML Core Services (aka MSXML) 3.0 does not properly handle HTTP responses, which allows remote attackers to execute arbitrary code or cause…EPSS 25%9.3CVE-2007-0099Microsoft xml core services race condition vulnerabilityRace condition in the msxml3 module in Microsoft XML Core Services 3.0, as used in Internet Explorer 6 and other applications, allows remote attacker…EPSS 25%8.8CVE-2016-0147Microsoft xml core services improper input validation vulnerabilityMicrosoft XML Core Services 3.0 allows remote attackers to execute arbitrary code via a crafted web site, aka "MSXML 3.0 Remote Code Execution Vulner…EPSS 16%8.8CVE-2013-0006Microsoft xml core services vulnerabilityMicrosoft XML Core Services (aka MSXML) 3.0, 5.0, and 6.0 does not properly parse XML content, which allows remote attackers to execute arbitrary cod…EPSS 28%7.6CVE-2006-5745Microsoft XML Core Services XMLHTTP ActiveX memory corruptionThe setRequestHeader method in the XMLHTTP ActiveX Control 4.0 shipped with Microsoft XML Core Services 4.0 on Windows contains a memory corruption f…EPSS 77%analysed

Source: NIST National Vulnerability Database (record CVE-2007-2223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.