CVE-2007-0213

Microsoft Exchange Server - Improper Input Validation

Title source: rule

Description

Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.

Exploits (1)

exploitdb WORKING POC
by Charles Truscott · pythonremotewindows
https://www.exploit-db.com/exploits/47076

Scores

EPSS 0.8339
EPSS Percentile 99.3%

Details

CWE
CWE-20
Status published
Products (3)
microsoft/exchange_server 2000 sp3
microsoft/exchange_server 2003 sp1 (2 CPE variants)
microsoft/exchange_server 2007
Published May 08, 2007
Tracked Since Feb 18, 2026