CVE-2007-0217
Status: ModifiedHigh (10)—💥 Exploit
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C
- Base score: 10
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 58%
- Percentile among all scored CVEs: 99
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · Microsoft Internet Explorer - FTP Server Response Denial of Service (MS07-016) (3/9/2007)
Affected technologies (2)
CWEs
- NVD-CWE-Other
References
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473
- http://secunia.com/advisories/24156
- http://www.kb.cert.org/vuls/id/613564
- http://www.osvdb.org/31892
- http://www.securityfocus.com/archive/1/462303/100/0/threaded
- http://www.securityfocus.com/bid/22489
- http://www.securitytracker.com/id?1017642
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.vupen.com/english/advisories/2007/0584
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141
- http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473
- http://secunia.com/advisories/24156
- http://www.kb.cert.org/vuls/id/613564
- http://www.osvdb.org/31892
- http://www.securityfocus.com/archive/1/462303/100/0/threaded
- http://www.securityfocus.com/bid/22489
- http://www.securitytracker.com/id?1017642
- http://www.us-cert.gov/cas/techalerts/TA07-044A.html
- http://www.vupen.com/english/advisories/2007/0584
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141
Raw JSON (NVD)
Show
{
"id": "CVE-2007-0217",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 10,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": true,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secure@microsoft.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2007-02-13T22:28:00.000",
"references": [
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473",
"source": "secure@microsoft.com"
},
{
"url": "http://secunia.com/advisories/24156",
"source": "secure@microsoft.com"
},
{
"url": "http://www.kb.cert.org/vuls/id/613564",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.osvdb.org/31892",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/archive/1/462303/100/0/threaded",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securityfocus.com/bid/22489",
"source": "secure@microsoft.com"
},
{
"url": "http://www.securitytracker.com/id?1017642",
"source": "secure@microsoft.com"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
"tags": [
"US Government Resource"
],
"source": "secure@microsoft.com"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0584",
"source": "secure@microsoft.com"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016",
"source": "secure@microsoft.com"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141",
"source": "secure@microsoft.com"
},
{
"url": "http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=473",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/24156",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.kb.cert.org/vuls/id/613564",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/31892",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/462303/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/22489",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securitytracker.com/id?1017642",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.us-cert.gov/cas/techalerts/TA07-044A.html",
"tags": [
"US Government Resource"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2007/0584",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-016",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1141",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption."
},
{
"lang": "es",
"value": "El código del cliente FTP wininet.dll en Microsoft Internet Explorer 5.01 y 6 podría permitir a atacantes remotos ejecutar código de su elección mediante una respuesta FTP del servidor de una longitud específica que provoca que el byte nulo de terminación sea escrito fuera del búfer, lo cual provoca la corrupción de la pila."
}
],
"lastModified": "2026-06-16T22:35:08.393",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:5.01:sp4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F3F2A51E-2675-4993-B9C2-F2D176A92857"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_2000:*:sp4:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "83E7C4A0-78CF-4B56-82BF-EC932BDD8ADF"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:ie:6.0:sp1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "24DF2AB3-DEAB-4D70-986E-FFBB7E64B96A"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:microsoft:windows_2003_server:gold:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "B058588A-88F3-4789-8EA9-0D37447B08CA"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2003_server:gold:*:itanium:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3C9649DB-D417-4CCC-9F61-685ECB355AD7"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2003_server:gold:*:x64:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "722526B1-12E3-42E7-95ED-84A86D0C189A"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "644E2E89-F3E3-4383-B460-424D724EE62F"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_2003_server:sp1:*:itanium:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7D11FC8D-59DD-4CAC-B4D3-DABB7A9903F1"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9B339C33-8896-4896-88FF-88E74FDBC543"
},
{
"criteria": "cpe:2.3:o:microsoft:windows_xp:*:sp2:professional_x64:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1AB9988B-5A9C-4F6D-BCCC-4D03AC6E4CF9"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:internet_explorer:6.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A19F6133-25D1-44A5-B6B9-354703436783"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "secure@microsoft.com"
}