Vulnerability record · CVE-2007-6165 · published 29 November 2007
CVE-2007-6165: Apple Mac OS X Mail AppleDouble attachment code execution
Apple · Mac Os X
Apple Mail in Mac OS X Leopard 10.5.1 fails to warn users when an AppleDouble attachment with an apparently safe file type hides an executable script in its resource fork. Opening such an attachment can run a separate program without the user's knowledge. This is a regression of CVE-2006-0395.
Description
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDouble attachment containing an apparently-safe file type and script in a resource fork, which does not warn the user that a separate program is going to be executed. NOTE: this is a regression error related to CVE-2006-0395.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote code execution with no authentication and a public exploit reference, though it requires the user to open an attachment and affects an old OS version.
What it is
Apple Mail in Mac OS X Leopard 10.5.1 fails to warn users when an AppleDouble attachment with an apparently safe file type hides an executable script in its resource fork. Opening such an attachment can run a separate program without the user's knowledge. This is a regression of CVE-2006-0395.
Impact
An attacker can execute arbitrary code with the privileges of the user who opens the attachment. Because the file appears safe, the user is unlikely to suspect anything until after execution.
Attack surface
Reached remotely by sending an email with a crafted AppleDouble attachment; no authentication is required, but the victim must open the attachment (user interaction). The CVSS vector AV:N/AC:M/Au:N confirms network delivery and medium attack complexity.
Exploitation
Not listed in CISA KEV. EPSS is 0.44746 (98.7th percentile), and a SecurityFocus reference is tagged Exploit, indicating public exploit information exists.
What to do
- Apply the Apple security update referenced in Apple advisory 307179 and US-CERT alert TA07-352A.
- Upgrade from Mac OS X 10.5.1 to a patched release.
- Disable automatic opening of attachments in Mail and train users not to open unexpected AppleDouble attachments.
- Block or strip AppleDouble resource-fork attachments at the email gateway where feasible.
Detection
- Search mail logs and quarantine for AppleDouble attachments containing resource forks or executable content.
- Monitor for unexpected child processes spawned by Mail.
- Alert on email attachments whose declared type differs from the content in the resource fork.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-6165 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-6165), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.