Vulnerability record · CVE-2007-4676 · published 7 November 2007
CVE-2007-4676: Apple QuickTime PICT parsing heap buffer overflow allows code execution
Apple · Mac Os X
Apple QuickTime before 7.3 contains a heap-based buffer overflow when parsing PICT images, specifically in the Poly type (0x0070-0x0074) and PackBitsRgn field (0x0099) opcodes. A malformed PICT image can corrupt heap memory, and because QuickTime is widely installed and often processes images automatically, this is a serious remote code execution risk.
Description
Heap-based buffer overflow in Apple QuickTime before 7.3 allows remote attackers to execute arbitrary code via malformed elements when parsing (1) Poly type (0x0070 through 0x0074) and (2) PackBitsRgn field (0x0099) opcodes in a PICT image.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityAlthough the vulnerability is old and not in KEV, the high CVSS score and very high EPSS percentile indicate significant exploitation potential, and QuickTime remains present in some environments.
What it is
Apple QuickTime before 7.3 contains a heap-based buffer overflow when parsing PICT images, specifically in the Poly type (0x0070-0x0074) and PackBitsRgn field (0x0099) opcodes. A malformed PICT image can corrupt heap memory, and because QuickTime is widely installed and often processes images automatically, this is a serious remote code execution risk.
Impact
A remote attacker can execute arbitrary code with the privileges of the user running QuickTime, leading to full compromise of confidentiality, integrity, and availability. The CVSS 2.0 vector (AV:N/AC:M/Au:N/C:C/I:C/A:C, score 9.3) reflects complete impact without authentication.
Attack surface
The flaw is reached by supplying a crafted PICT image to QuickTime, typically via a web page, email attachment, or file opened by the user. No authentication is required, but some user interaction (opening or viewing the image) is needed per the AC:M vector.
Exploitation
The record is not listed in CISA KEV and no ransomware groups are documented using it, but EPSS is 0.46662 (98.8th percentile), indicating a high predicted likelihood of exploitation activity. References include Zero Day Initiative advisories, suggesting coordinated disclosure of a remotely exploitable issue.
What to do
- Upgrade Apple QuickTime to version 7.3 or later, which contains the fix per the vendor advisory.
- If QuickTime cannot be updated, disable or remove the PICT image handler and avoid opening untrusted PICT files.
- Block PICT file attachments and downloads at email and web gateways where feasible.
- Apply the Microsoft security updates referenced for Windows Vista and Windows XP systems running QuickTime.
- Restrict user privileges so that successful exploitation does not yield administrative rights.
Detection
- Monitor for QuickTime or related processes spawning unexpected child processes or making outbound network connections after opening image files.
- Search endpoint logs for crashes or heap corruption events in QuickTime components when processing PICT files.
- Inspect email and web proxy logs for PICT attachments or downloads from untrusted sources.
- Use file inspection or sandboxing to flag malformed PICT files containing Poly (0x0070-0x0074) or PackBitsRgn (0x0099) opcodes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-4676 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-4676), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.