← Vulnerability feed

Vulnerability record · CVE-2007-4336 · published 14 August 2007

CVE-2007-4336: Microsoft DirectX Media FlashPix ActiveX control buffer overflow

Microsoft · Directx Media

The DXSurface.LivePicture.FlashPix.1 ActiveX control in DXTLIPI.DLL 6.0.2.827, shipped in the Microsoft DirectX Media 6.0 SDK, contains a buffer overflow reachable through a long SourceUrl property value. A remote attacker can trigger it to run arbitrary code in the context of the user who loads the control. The record is old and thin: no vendor patch reference is given, and the CWE is only the generic NVD-CWE-Other.

4.3 CVSS 2.0 Medium EPSS 51% · top 1.1%
4.3CVSS 2.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX control in DXTLIPI.DLL 6.0.2.827, as packaged in Microsoft DirectX Media 6.0 SDK, allows remote attackers to execute arbitrary code via a long SourceUrl property value.

AV:N/AC:M/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityPublic exploit code and a very high EPSS score make this legacy ActiveX overflow a realistic target wherever the control remains installed, despite the medium CVSS 2.0 base score.

What it is

The DXSurface.LivePicture.FlashPix.1 ActiveX control in DXTLIPI.DLL 6.0.2.827, shipped in the Microsoft DirectX Media 6.0 SDK, contains a buffer overflow reachable through a long SourceUrl property value. A remote attacker can trigger it to run arbitrary code in the context of the user who loads the control. The record is old and thin: no vendor patch reference is given, and the CWE is only the generic NVD-CWE-Other.

Impact

Successful exploitation gives the attacker arbitrary code execution with the privileges of the process hosting the ActiveX control, typically the logged-on user. The CVSS 2.0 vector rates only partial availability impact, but the description states code execution, so the scoring and the flaw description do not fully agree.

Attack surface

Reached over the network by a page or document that instantiates the ActiveX control and sets a long SourceUrl property; the vector AV:N/AC:M/Au:N indicates no authentication is required but some user action, such as visiting a malicious page, is needed. The control must be present and permitted to run in the victim's browser or host application.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at 0.507 (98.9th percentile) and a public Exploit-DB entry (4279) exists, so working exploit code is publicly available.

What to do

  • Remove or unregister DXTLIPI.DLL / the DXSurface.LivePicture.FlashPix.1 control where DirectX Media 6.0 SDK components are not required.
  • Apply any Microsoft update or kill-bit guidance for this control; the record itself provides no patch reference, so confirm current vendor status before relying on it.
  • Restrict ActiveX execution in browsers and other hosts, and block untrusted sites from instantiating this CLSID.
  • Treat DirectX Media 6.0 SDK as legacy and retire it from production systems.

Detection

  • Hunt for processes loading DXTLIPI.DLL or instantiating the DXSurface.LivePicture.FlashPix.1 CLSID.
  • Monitor for crashes or memory corruption in browser and ActiveX host processes following visits to untrusted pages.
  • Search proxy and web logs for pages or documents that reference the FlashPix ActiveX control or SourceUrl property.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-4336 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2007-4336), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.