← Vulnerability feed

Vulnerability record · CVE-2007-6357 · published 15 December 2007

CVE-2007-6357: Microsoft access memory buffer overflow vulnerability

Microsoft · Access

Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.

5.8 CVSS 2.0 Medium EPSS 16% · top 3.2% CWE-119 · Memory buffer overflow
5.8CVSS 2.0 base score
16%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in Microsoft Office Access allows remote, user-assisted attackers to execute arbitrary code via a crafted Microsoft Access Database (.mdb) file. NOTE: due to the lack of details as of 20071210, it is not clear whether this issue is the same as CVE-2007-6026 or CVE-2005-0944.

AV:N/AC:M/Au:N/C:P/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-6357 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2007-0671Microsoft Excel remote code execution via malformed fileCVE-2007-0671 is an unspecified vulnerability in Microsoft Excel 2000, XP, 2003, and 2004 for Mac, and possibly other Office products, that allows re…KEVEPSS 43%analysed10.0CVE-2000-0788Microsoft access vulnerabilityThe Mail Merge tool in Microsoft Word does not prompt the user before executing Visual Basic (VBA) scripts in an Access database, which could allow a…EPSS 8.4%10.0CVE-1999-0364Fms inc. total vb sourcebook vulnerabilityMicrosoft Access 97 stores a database password as plaintext in a foreign mdb, allowing access to data.EPSS 5.2%9.3CVE-2015-2503Microsoft access permissions and access controls vulnerabilityMicrosoft Access 2007 SP3, Excel 2007 SP3, InfoPath 2007 SP3, OneNote 2007 SP3, PowerPoint 2007 SP3, Project 2007 SP3, Publisher 2007 SP3, Visio 2007…EPSS 17%9.3CVE-2013-3155Microsoft access memory buffer overflow vulnerabilityMicrosoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…EPSS 20%9.3CVE-2013-3156Microsoft access memory buffer overflow vulnerabilityMicrosoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…EPSS 20%9.3CVE-2013-3157Microsoft access memory buffer overflow vulnerabilityMicrosoft Access 2007 SP3, 2010 SP1 and SP2, and 2013 in Microsoft Office allows remote attackers to execute arbitrary code or cause a denial of serv…EPSS 19%9.3CVE-2010-0814Microsoft access code injection vulnerabilityThe Microsoft Access Wizard Controls in ACCWIZ.dll in Microsoft Office Access 2003 SP3 and 2007 SP1 and SP2 do not properly interact with the memory-…EPSS 23%

Source: NIST National Vulnerability Database (record CVE-2007-6357), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.