First published: Thu Oct 18 2007(Updated: )
The SMS handler for Windows Mobile 2005 Pocket PC Phone edition allows attackers to hide the sender field of an SMS message via a malformed WAP PUSH message that causes the PDU to be incorrectly decoded.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Windows Mobile Connectivity Tools | =2005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5493 is classified as a moderate severity vulnerability due to potential risks of SMS message spoofing.
CVE-2007-5493 allows attackers to hide the sender field of SMS messages on Windows Mobile 2005, misleading users.
To mitigate CVE-2007-5493, users should apply any available security patches for Windows Mobile 2005.
Users of Microsoft Windows Mobile 2005 Pocket PC Phone edition are affected by CVE-2007-5493.
The attack vector for CVE-2007-5493 involves delivering a malformed WAP PUSH message to a vulnerable Windows Mobile device.