CVE-2007-0221
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 37.2%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
Integer overflow in the IMAP (IMAP4) support in Microsoft Exchange Server 2000 SP3 allows remote attackers to cause a denial of service (service hang) via crafted literals in an IMAP command, aka the "IMAP Literal Processing Vulnerability."
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
- EPSS
- 37.24% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-190
- Affected
- microsoft/exchange server
- Source
- secure@microsoft.com
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526Patch, Third Party Advisory
- http://secunia.com/advisories/25183Patch, Third Party Advisory
- http://www.osvdb.org/34392Broken Link
- http://www.securityfocus.com/archive/1/468871/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23810Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018015Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/1711Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33890Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2054Third Party Advisory
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=526Patch, Third Party Advisory
- http://secunia.com/advisories/25183Patch, Third Party Advisory
- http://www.osvdb.org/34392Broken Link
- http://www.securityfocus.com/archive/1/468871/100/200/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/23810Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018015Patch, Third Party Advisory, VDB Entry
- http://www.us-cert.gov/cas/techalerts/TA07-128A.htmlThird Party Advisory, US Government Resource
- http://www.vupen.com/english/advisories/2007/1711Permissions Required
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-026Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33890Third Party Advisory, VDB Entry
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2054Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.