CVE-2007-0220
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.1%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Cross-site scripting (XSS) vulnerability in Outlook Web Access (OWA) in Microsoft Exchange Server 2000 SP3, and 2003 SP1 and SP2 allows remote attackers to execute arbitrary scripts, spoof content, or obtain sensitive information via certain UTF-encoded, script-based e-mail attachments, involving an "incorrectly handled UTF character set label".
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 33.15% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- microsoft/exchange server
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/25183Third Party Advisory
- http://www.kb.cert.org/vuls/id/124113Third Party Advisory, US Government Resource
- http://www.osvdb.org/34389Broken Link
- http://www.securityfocus.com/archive/1/468871/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23806Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018015Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/1711Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33887Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371Third Party Advisory
- http://secunia.com/advisories/25183Third Party Advisory
- http://www.kb.cert.org/vuls/id/124113Third Party Advisory, US Government Resource
- http://www.osvdb.org/34389Broken Link
- http://www.securityfocus.com/archive/1/468871/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23806Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018015Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/1711Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026Patch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33887Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1371Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.