CVE-2007-1578 describes multiple integer signedness errors in the NTLM implementation of Atrium MERCUR IMAPD (mcrimap4.exe) version 5.00.14 with SP4. This vulnerability allows remote, unauthenticated attackers to execute arbitrary code by sending a specially crafted, long NTLMSSP argument that triggers a stack-based buffer overflow. With a CVSS score of 10.0, this critical vulnerability poses a severe risk, enabling complete compromise of confidentiality, integrity, and availability. While no active exploitation is confirmed, a denial-of-service exploit exists on ExploitDB, and the vulnerability has a high EPSS score, indicating a significant probability of exploitation. Despite its severity, there is no evidence of Metasploit or Nuclei modules, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.00.14CPE matchmatch criteria | cpe:2.3:a:atrium_software:mercur_imapd:5.00.14:sp4:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.