Vulnerability record · CVE-2007-0213 · published 8 May 2007
CVE-2007-0213: Microsoft Exchange MIME base64 decoding remote code execution
Microsoft · Exchange Server
Microsoft Exchange Server 2000 SP3, 2003 SP1/SP2, and 2007 fail to properly decode certain MIME-encoded emails, allowing remote code execution via a crafted base64-encoded MIME message. The flaw is an input validation failure in MIME handling that can be triggered by a specially crafted email.
Description
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, which allows remote attackers to execute arbitrary code via a crafted base64-encoded MIME e-mail message.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityCVSS 2.0 score of 10 with network reachability, no authentication, and complete impact, combined with a high EPSS percentile, warrants critical priority despite the lack of KEV listing.
What it is
Microsoft Exchange Server 2000 SP3, 2003 SP1/SP2, and 2007 fail to properly decode certain MIME-encoded emails, allowing remote code execution via a crafted base64-encoded MIME message. The flaw is an input validation failure in MIME handling that can be triggered by a specially crafted email.
Impact
A remote attacker can execute arbitrary code with the privileges of the Exchange service, potentially leading to full system compromise. The CVSS 2.0 vector indicates complete confidentiality, integrity, and availability impact.
Attack surface
The vulnerability is reachable over the network via email (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated in the vector or description.
Exploitation
The record does not list this CVE in CISA KEV, and no ransomware groups are documented as using it. EPSS probability is 0.6616 (99.241 percentile), suggesting a high likelihood of exploitation activity, but no public exploit tags are present in the references.
What to do
- Apply the vendor patch referenced in Microsoft Security Bulletin MS07-026.
- Disable or restrict unnecessary MIME processing features on affected Exchange servers.
- Filter or block base64-encoded MIME emails with malformed or suspicious structures at the email gateway.
- Upgrade to a supported Exchange version if still running Exchange 2000, 2003, or 2007.
Detection
- Monitor Exchange server logs for crashes or unexpected process terminations related to MIME decoding.
- Inspect email gateway logs for base64-encoded MIME messages with anomalous encoding patterns.
- Use network monitoring to detect unusual outbound connections from Exchange servers that may indicate post-exploitation activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0213 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.