Vulnerability record · CVE-2007-2238 · published 16 April 2009
CVE-2007-2238: Microsoft IAG Whale Client ActiveX control stack buffer overflow
Microsoft · Intelligent Application Gateway 2007
The Whale Client Components ActiveX control (WhlMgr.dll) shipped with Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2 contains multiple stack-based buffer overflows in its CheckForUpdates and UpdateComponents methods. Passing overly long arguments to these methods corrupts the stack, letting an attacker run arbitrary code in the context of the browser process that loaded the control. The flaw matters because the control is reachable from web content and the affected product is a remote-access gateway.
Description
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2, allow remote attackers to execute arbitrary code via long arguments to the (1) CheckForUpdates or (2) UpdateComponents methods.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with a 9.3 CVSS and very high EPSS, tempered by the need for user interaction and a browser that runs the ActiveX control.
What it is
The Whale Client Components ActiveX control (WhlMgr.dll) shipped with Microsoft Intelligent Application Gateway (IAG) before 3.7 SP2 contains multiple stack-based buffer overflows in its CheckForUpdates and UpdateComponents methods. Passing overly long arguments to these methods corrupts the stack, letting an attacker run arbitrary code in the context of the browser process that loaded the control. The flaw matters because the control is reachable from web content and the affected product is a remote-access gateway.
Impact
An attacker who can get the vulnerable ActiveX control instantiated gains arbitrary code execution with the privileges of the user running the browser, which on a gateway or admin workstation can mean full control of that host.
Attack surface
Reached over the network by a page that instantiates the WhlMgr.dll ActiveX control and calls CheckForUpdates or UpdateComponents with long arguments; no authentication is required, but the victim must load the attacker's content in a browser that permits the control to run, so user interaction is needed.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is recorded in this data, but EPSS is 0.455 (98.7th percentile), indicating a high modeled likelihood of exploitation activity.
What to do
- Apply the IAG 3.7 SP2 or later update that fixes WhlMgr.dll, and confirm the patched control version is deployed.
- Remove or kill-bit the Whale Client Components ActiveX control where IAG client components are not required.
- Restrict browsing from IAG gateway and administrative hosts, and block untrusted sites from loading ActiveX controls.
- Enforce least privilege so browser processes cannot execute code with elevated rights.
Detection
- Monitor for WhlMgr.dll being loaded by browser processes and for calls to CheckForUpdates or UpdateComponents.
- Alert on browser or child process crashes consistent with stack corruption on hosts that use IAG client components.
- Hunt for unexpected child processes spawned by browsers on IAG gateway or admin systems.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2238 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2238), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.