{"api_version":"1","generated_at":"2026-07-23T12:02:37+00:00","cve":"CVE-2007-1535","urls":{"html":"https://cve.report/CVE-2007-1535","api":"https://cve.report/api/cve/CVE-2007-1535.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1535","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1535"},"summary":{"title":"CVE-2007-1535","description":"Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-20 20:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/464617/100/0/threaded","name":"http://www.securityfocus.com/archive/1/464617/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/33667","name":"http://osvdb.org/33667","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/462793/100/0/threaded","name":"http://www.securityfocus.com/archive/1/462793/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf","name":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"symantec.com has moved to broadcom.com","mime":"application/pdf","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/23267","name":"http://www.securityfocus.com/bid/23267","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows Vista Teredo Protocol Insecure Connection Weakness","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html","name":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Symantec Security Response Weblog: Microsoft's Inaccurate Teredo Documentation, and Other Vista CVEs","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1535","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1535","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1535","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:59:08.601Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"33667","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33667"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"},{"name":"20070313 New report on Windows Vista network attack surface","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/462793/100/0/threaded"},{"name":"20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/464617/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"},{"name":"23267","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/23267"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-03-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"33667","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33667"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"},{"name":"20070313 New report on Windows Vista network attack surface","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/462793/100/0/threaded"},{"name":"20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/464617/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"},{"name":"23267","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/23267"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1535","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"33667","refsource":"OSVDB","url":"http://osvdb.org/33667"},{"name":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf","refsource":"MISC","url":"http://www.symantec.com/avcenter/reference/Vista_Network_Attack_Surface_RTM.pdf"},{"name":"20070313 New report on Windows Vista network attack surface","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/462793/100/0/threaded"},{"name":"20070403 Nine Vista CVEs, including Microsoft inaccurate Teredo use case documentation","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/464617/100/0/threaded"},{"name":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html","refsource":"MISC","url":"http://www.symantec.com/enterprise/security_response/weblog/2007/04/microsofts_inaccurate_teredo_d.html"},{"name":"23267","refsource":"BID","url":"http://www.securityfocus.com/bid/23267"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1535","datePublished":"2007-03-20T20:00:00.000Z","dateReserved":"2007-03-20T00:00:00.000Z","dateUpdated":"2024-08-07T12:59:08.601Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-20 20:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*","matchCriteriaId":"3852BB02-47A1-40B3-8E32-8D8891A53114"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1535","Ordinal":"1","Title":"CVE-2007-1535","CVE":"CVE-2007-1535","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1535","Ordinal":"1","NoteData":"Microsoft Windows Vista establishes a Teredo address without user action upon connection to the Internet, contrary to documentation that Teredo is inactive without user action, which increases the attack surface and allows remote attackers to communicate via Teredo.","Type":"Description","Title":"CVE-2007-1535"},{"CveYear":"2007","CveId":"1535","Ordinal":"2","NoteData":"2007-03-20","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1535","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}