Vulnerability Intelligence Report
CVE-2007-3300
Multiple F-Secure anti-virus products for Microsoft Windows and Linux before 20070619 allow remote attackers to bypass scanning via a crafted header in a (1) LHA or (2) RAR archive.
No Active Exploit Signals
CVSS Base Score
9.3
HIGH
EPSS Probability:3.71%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| f-secure | f-secure_anti-virus | 2.16, 4.51, 4.52, 4.61, 4.64, 4.65, 5.0.2, 5.2.1, 5.3.0, 5.5, 5.40, 5.41, 5.42, 5.43, 5.44, 5.52, 5.54, 5.55, 5.56, 5.61, 6.01, 6.02, 6.2, 6.03, 6.21, 6.30, 6.30_sr1, 6.31, 6.40, 6.60, 6.61, 7.00, 2005, 2006, 2007 |
| f-secure | f-secure_anti-virus_linux_client_security | all |
| f-secure | f-secure_anti-virus_linux_server_security | all |
| f-secure | f-secure_internet_security | 2005, 2006, 2007 |
| f-secure | internet_gatekeeper | 2.06, 2.14, 2.15.484, 2.16 |
| f-secure | solutions_based_on_f-secure_personal_express | 6.20 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.711%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2007-06-20T00:00:00 |
| Published | 2007-06-20T22:00:00 |
| Patch Date | 2007-06-19 |
| Last Updated | 2024-08-07T14:14:12 |
Community Chatter & Buzz