← Vulnerability feed

Vulnerability record · CVE-2007-0938 · published 10 April 2007

CVE-2007-0938: Microsoft Content Management Server memory corruption via crafted HTTP GET

Microsoft · Content Management Server

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 mishandles certain characters in a crafted HTTP GET request, causing memory corruption. A remote, unauthenticated attacker can trigger this to execute arbitrary code on the server. The flaw is remotely reachable and rated maximum severity by CVSS 2.0.

10.0 CVSS 2.0 High EPSS 46% · top 1.2%
10.0CVSS 2.0 base score
46%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 does not properly handle certain characters in a crafted HTTP GET request, which allows remote attackers to execute arbitrary code, aka the "CMS Memory Corruption Vulnerability."

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS 2.0 base score of 10 with network, unauthenticated, low-complexity code execution on an internet-reachable server, and high EPSS, warrant critical treatment despite no KEV listing.

What it is

Microsoft Content Management Server (MCMS) 2001 SP1 and 2002 SP2 mishandles certain characters in a crafted HTTP GET request, causing memory corruption. A remote, unauthenticated attacker can trigger this to execute arbitrary code on the server. The flaw is remotely reachable and rated maximum severity by CVSS 2.0.

Impact

Successful exploitation lets a remote attacker run arbitrary code with the privileges of the MCMS service, giving full control of confidentiality, integrity and availability on the host. No privilege escalation step is needed beyond reaching the service.

Attack surface

Reached over the network via a crafted HTTP GET request to the affected MCMS server; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and no user interaction are required. Any internet- or intranet-exposed MCMS instance is a candidate target.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.45633, 98.7th percentile), suggesting meaningful likelihood of attempted exploitation. Reference tags are generic (one US Government Resource); no public exploit or in-the-wild confirmation is stated in the record.

What to do

  • Apply Microsoft security bulletin MS07-018 for MCMS 2001 SP1 and 2002 SP2, or upgrade to a supported platform if MCMS is end-of-life.
  • Restrict network access to MCMS HTTP endpoints to trusted networks and place them behind a reverse proxy or WAF that filters malformed GET requests.
  • Run the MCMS service under a least-privilege account to limit the impact of code execution.
  • Monitor vendor guidance and retire unsupported MCMS deployments, since no further fixes will be issued.

Detection

  • Inspect web server and MCMS logs for HTTP GET requests containing unusual or malformed characters and correlate with process crashes or restarts.
  • Alert on unexpected child processes or command shells spawned by the MCMS worker process.
  • Monitor for memory corruption indicators such as w3wp/MCMS service crashes and repeated 500 responses on the same endpoint.
  • Use the OVAL definition referenced in the record to check host patch state for MS07-018.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-0938 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-0938), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.