peter bassill · operator
$ cve CVE-2007-3201 JSON

CVE-2007-3201 EXPLOIT

7.1
HIGH · CVSS 2.0 · EPSS 2.7% (pctl 86)

Patch early

A public exploit exists.

Description

Visual truncation vulnerability in Windows Privacy Tray (WinPT) 1.2.0 allows user-assisted remote attackers to install a key listed under the wrong user ID, and possibly cause the user to encrypt a victim's correspondence with this attacker-supplied key, via a key ID composed of the attacker's user ID, space characters, an invalid WinPT message, additional space characters, and the victim's user ID.

Scoring

CVSS7.1 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:C/A:N
EPSS2.71% — more likely to be exploited than 86% of all CVEs
On CISA KEVno
Public exploityes
Published2007-06-12
Last modified2026-06-16

Affected (1)

VendorProduct
winptwinpt

Public exploits

SourceTitleDate
exploit-dbWindowsPT 1.2 - User ID Key Spoofing2007-06-11

References

→ the Explorer  ·  watch your stack  ·  NVD