CVE-2007-5493: Medium severity Microsoft Windows Mobile vulnerability
Published Oct 18, 2007
·Updated
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.
Affected Software
1 affected component
Microsoft Windows Mobile=2005
Event History
Oct 18, 2007
CVE Published
12:17 AM
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5493?
CVE-2007-5493 is classified as a moderate severity vulnerability due to potential risks of SMS message spoofing.
2
How does CVE-2007-5493 affect Windows Mobile devices?
CVE-2007-5493 allows attackers to hide the sender field of SMS messages on Windows Mobile 2005, misleading users.
3
How do I fix CVE-2007-5493?
To mitigate CVE-2007-5493, users should apply any available security patches for Windows Mobile 2005.
4
Who is affected by CVE-2007-5493?
Users of Microsoft Windows Mobile 2005 Pocket PC Phone edition are affected by CVE-2007-5493.
5
What is the attack vector for CVE-2007-5493?
The attack vector for CVE-2007-5493 involves delivering a malformed WAP PUSH message to a vulnerable Windows Mobile device.