← Vulnerability feed

Vulnerability record · CVE-2007-5493 · published 18 October 2007

CVE-2007-5493: Microsoft windows mobile permissions and access controls vulnerability

Microsoft · Windows Mobile

The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

4.3 CVSS 2.0 Medium EPSS 4.2% · top 9.4% CWE-264 · Permissions and access controls
4.3CVSS 2.0 base score
4.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-5493 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2006-6908Broadcom widcomm bluetooth vulnerabilityBuffer overflow in the Bluetooth Stack COM Server in the Widcomm Bluetooth stack, as packaged as Widcomm Stack 3.x and earlier on Windows, Widcomm BT…EPSS 30%8.8CVE-2009-0244Microsoft windows mobile path traversal vulnerabilityDirectory traversal vulnerability in the OBEX FTP Service in the Microsoft Bluetooth stack in Windows Mobile 6 Professional, and probably Windows Mob…EPSS 30%7.8CVE-2007-0878Microsoft windows mobile vulnerabilityUnspecified vulnerability in Microsoft Internet Explorer on Windows Mobile 5.0 allows remote attackers to cause a denial of service (loss of browser …EPSS 20%7.1CVE-2007-0674Microsoft windows mobile vulnerabilityPictures and Videos on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows user-assisted remote attackers to ca…EPSS 17%5.4CVE-2008-4295Microsoft windows mobile improper input validation vulnerabilityMicrosoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to establish a Bluetooth connection …EPSS 30%4.6CVE-2007-5460Microsoft windows mobile broken cryptographic algorithm vulnerabilityMicrosoft ActiveSync 4.1, as used in Windows Mobile 5.0, uses weak encryption (XOR obfuscation with a fixed key) when sending the user's PIN/Password…EPSS 2.2%2.6CVE-2007-0685Microsoft windows mobile vulnerabilityInternet Explorer on Windows Mobile 5.0 and Windows Mobile 2003 and 2003SE for Smartphones and PocketPC allows attackers to cause a denial of service…EPSS 5.8%2.1CVE-2008-4540Microsoft windows mobile vulnerabilityWindows Mobile 6 on the HTC Hermes device makes WLAN passwords available to an auto-completion mechanism for the password input field, which allows p…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2007-5493), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.