Vulnerability record · CVE-2007-2223 · published 14 August 2007
CVE-2007-2223: Microsoft XML Core Services substringData integer overflow RCE
Microsoft · Xml Core Services
MSXML 3.0 through 6.0 contains an integer overflow in the substringData method on TextNode and XMLDOM objects that leads to a buffer overflow. A remote attacker can trigger it to run arbitrary code in the context of the affected process, making it a serious code execution flaw in a widely deployed XML parser.
Description
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringData method on a (1) TextNode or (2) XMLDOM object, which causes an integer overflow that leads to a buffer overflow.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote unauthenticated code execution with complete impact and a very high EPSS percentile, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
MSXML 3.0 through 6.0 contains an integer overflow in the substringData method on TextNode and XMLDOM objects that leads to a buffer overflow. A remote attacker can trigger it to run arbitrary code in the context of the affected process, making it a serious code execution flaw in a widely deployed XML parser.
Impact
Successful exploitation lets a remote attacker execute arbitrary code with the privileges of the application using MSXML, potentially leading to full system compromise. The CVSS 2.0 vector rates complete confidentiality, integrity and availability impact.
Attack surface
Reachable over the network (AV:N) with no authentication required (Au:N), but the CVSS vector notes medium access complexity (AC:M), implying some precondition such as a crafted document being parsed or a user being induced to open it. No user interaction detail is given beyond the vector.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at 0.487 (98.8th percentile), indicating elevated predicted exploitation likelihood. References are advisories and a vendor patch bulletin, with no public exploit tag supplied.
What to do
- Apply the Microsoft security bulletin MS07-042 patch for MSXML immediately.
- Inventory systems and applications that load MSXML 3.0 through 6.0, including legacy Office and browser-dependent components.
- Restrict processing of untrusted XML documents and disable or block risky MSXML object instantiation where feasible.
- Where patching is not possible, isolate affected hosts and limit outbound and lateral network access.
Detection
- Monitor for crashes or abnormal process termination in applications that parse XML, especially those loading msxml3.dll through msxml6.dll.
- Hunt for suspicious child processes spawned by Office, browser or script host processes that use MSXML.
- Review endpoint logs for exploitation artifacts around XML parsing and unusual memory corruption indicators.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2223 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2223), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.