Vulnerability record · CVE-2007-3040 · published 12 September 2007
CVE-2007-3040: Microsoft Agent ActiveX Control Stack Buffer Overflow on Windows 2000
Microsoft · Windows 2000
A stack-based buffer overflow exists in agentdpv.dll 2.0.0.3425 within Microsoft Agent on Windows 2000 SP4. A crafted URL passed to the Agent (Agent.Control) ActiveX control overflows a buffer inside the Agent Service (agentsrv.exe) process. This is a distinct issue from CVE-2007-1205.
Description
Stack-based buffer overflow in agentdpv.dll 2.0.0.3425 in Microsoft Agent on Windows 2000 SP4 allows remote attackers to execute arbitrary code via a crafted URL to the Agent (Agent.Control) ActiveX control, which triggers an overflow within the Agent Service (agentsrv.exe) process, a different issue than CVE-2007-1205.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with complete impact and a very high EPSS score, though limited to the legacy Windows 2000 SP4 platform and requiring medium access complexity.
What it is
A stack-based buffer overflow exists in agentdpv.dll 2.0.0.3425 within Microsoft Agent on Windows 2000 SP4. A crafted URL passed to the Agent (Agent.Control) ActiveX control overflows a buffer inside the Agent Service (agentsrv.exe) process. This is a distinct issue from CVE-2007-1205.
Impact
A remote attacker can execute arbitrary code in the context of the Agent Service process. Successful exploitation gives full compromise of confidentiality, integrity and availability on the affected host.
Attack surface
Reachable over the network via a crafted URL delivered to the Agent ActiveX control; the CVSS vector AV:N/AC:M/Au:N indicates no authentication is required, though some user interaction or a non-trivial condition is implied by the medium access complexity.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.54428, 98.9th percentile), and references include vendor patch and US-CERT advisories, but no public exploit tag is present in the record.
What to do
- Apply Microsoft security bulletin MS07-051 to update agentdpv.dll and the Agent Service.
- Disable or remove the Microsoft Agent ActiveX control where it is not required.
- Restrict or block untrusted URLs and ActiveX content reaching the Agent control via browser or email.
- Upgrade or retire Windows 2000 SP4 systems, which no longer receive current security support.
- Apply the vendor patch referenced by Secunia advisory 26753.
Detection
- Monitor for crashes or abnormal termination of agentsrv.exe.
- Alert on suspicious URL or ActiveX instantiation patterns targeting the Agent control.
- Review host logs for unexpected child processes spawned by agentsrv.exe.
- Track unpatched Windows 2000 SP4 hosts still exposing the Agent control.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3040 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3040), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.