CVE-2009-0098
Published Feb 10, 2009
Last updated 6 years ago
Overview
- Description
- Microsoft Exchange 2000 Server SP3, Exchange Server 2003 SP2, and Exchange Server 2007 SP1 do not properly interpret Transport Neutral Encapsulation (TNEF) properties, which allows remote attackers to execute arbitrary code via a crafted TNEF message, aka "Memory Corruption Vulnerability."
- Source
- secure@microsoft.com
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 9.3
- Impact score
- 10
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- CWE-399
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:microsoft:exchange_server:2000:sp3:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E88E31D4-1120-4A18-BA65-E2C96B35E599" }, { "criteria": "cpe:2.3:a:microsoft:exchange_server:2003:sp2:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "71A2E549-5F21-4842-BEB3-380CD4029C16" }, { "criteria": "cpe:2.3:a:microsoft:exchange_server:2007:sp1:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "9C218952-1BB8-4915-B31F-9D23543FC83E" } ], "operator": "OR" } ] } ]