peter bassill · operator
$ cve CVE-2007-3039 JSON

CVE-2007-3039 EXPLOIT

9.0
HIGH · CVSS 2.0 · EPSS 69.1% (pctl 99)

Patch early

A public exploit exists.

Description

Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

Scoring

CVSS9.0 (HIGH, v2.0)
VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
EPSS69.06% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2007-12-12
Last modified2026-06-16

Affected (3)

VendorProduct
microsoftmessage queuing
microsoftwindows 2000
microsoftwindows xp

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD