CVE-2007-0675

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
03/02/2007
Last modified:
09/04/2025

Description

A certain ActiveX control in sapi.dll (aka the Speech API) in Speech Components in Microsoft Windows Vista, when the Speech Recognition feature is enabled, allows user-assisted remote attackers to delete arbitrary files, and conduct other unauthorized activities, via a web page with an embedded sound object that contains voice commands to an enabled microphone, allowing for interaction with Windows Explorer.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:microsoft:windows_vista:*:*:32_bit:*:*:*:*:*


References to Advisories, Solutions, and Tools