RULE(RULE ID:306804)

Rule General Information
Release Date: 2014-11-18
Rule Name: Microsoft Windows Vista Feed Headlines Gadget Code Execution Vulnerability -1 (CVE-2007-3033)
Severity:
CVE ID:
Rule Protection Details
Description: Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows
Reference: MicrosoftSecurityBulletin:ms07-048
SecurityFocusBID:25287
SecurityTrackerID:1018566
Solutions
Microsoft has released a patch MS07-048 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms07-048.mspx