CVE-2007-0213 describes a critical remote code execution vulnerability affecting Microsoft Exchange Server 2000 SP3, 2003 SP1/SP2, and 2007. The flaw stems from improper decoding of specially crafted base64-encoded MIME email messages, allowing unauthenticated attackers to execute arbitrary code on vulnerable servers. With a CVSS score of 10.0 and an EPSS score indicating high exploitability, this vulnerability poses a severe risk, enabling full compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog or showing active social media discussion, public exploit code exists, demonstrating its potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2000CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2003:sp1:*:*:*:*:*:* | ||
2003CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:* | ||
2007CPE matchmatch criteria | cpe:2.3:a:microsoft:exchange_server:2007:-:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.