CVE-2007-0039

high Microsoft
CVSS v3 Base Score
7.8
AV:N/AC:L/Au:N/C:N/I:N/A:C
EPSS Score
39.6%
Exploitation probability in 30 days
Top 3% most likely to be exploited
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Confidentiality
None
Integrity
None
Availability
C
Published: May 8, 2007 (6945 days ago)
Last Modified: April 23, 2026
Vendor: Microsoft
Source: NVD

Description

The Exchange Collaboration Data Objects (EXCDO) functionality in Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 allows remote attackers to cause a denial of service (crash) via an Internet Calendar (iCal) file containing multiple X-MICROSOFT-CDO-MODPROPS (MODPROPS) properties in which the second MODPROPS is longer than the first, which triggers a NULL pointer dereference and an unhandled exception.

CWE

CWE-476

Affected Products

microsoft exchange server

References