{"api_version":"1","generated_at":"2026-07-23T08:38:17+00:00","cve":"CVE-2007-3038","urls":{"html":"https://cve.report/CVE-2007-3038","api":"https://cve.report/api/cve/CVE-2007-3038.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-3038","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-3038"},"summary":{"title":"CVE-2007-3038","description":"The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka \"Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability.\"","state":"PUBLISHED","assigner":"microsoft","published_at":"2007-07-10 22:30:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.8","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"http://osvdb.org/35952","name":"http://osvdb.org/35952","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt","name":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"symantec.com has moved to broadcom.com","mime":"text/plain","httpstatus":"404","archivestatus":"200"},{"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html","name":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Technical Cyber Security Alert TA07-191A -- Microsoft Updates for Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/26001","name":"http://secunia.com/advisories/26001","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows Vista Firewall Teredo Blocking Rule Security Bypass - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35322","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35322","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/24779","name":"http://www.securityfocus.com/bid/24779","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Windows Vista Teredo Interface Firewall Bypass Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/101321","name":"http://www.kb.cert.org/vuls/id/101321","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#101321","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securitytracker.com/id?1018354","name":"http://www.securitytracker.com/id?1018354","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Windows Vista Firewall Teredo Interface Discloses Network Information to Remote Users and May Let Remote Users Bypass Firewall Rules - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/2480","name":"http://www.vupen.com/english/advisories/2007/2480","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038","name":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Microsoft Security Bulletin MS07-038 - Moderate | Microsoft Docs","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/473294/100/0/threaded","name":"http://www.securityfocus.com/archive/1/473294/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1884","name":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1884","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Repository  /  Oval Repository","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html","name":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[security bulletin] HPSBST02243 SSRT071446 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS07-036 to MS07-041","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-3038","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-3038","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"3038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2007","cve_id":"3038","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows_vista","cpe6":"*","cpe7":"*","cpe8":"x64","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T13:57:54.941Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"SSRT071446","tags":["vendor-advisory","x_refsource_HP","x_transferred"],"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"win-vista-firewall-information-disclosure(35322)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35322"},{"name":"ADV-2007-2480","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/2480"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt"},{"name":"24779","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/24779"},{"name":"oval:org.mitre.oval:def:1884","tags":["vdb-entry","signature","x_refsource_OVAL","x_transferred"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1884"},{"name":"20070709 SYMSA-2007-005: Vista Windows Firewall Incorrectly Applies Filtering to Teredo Interface","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/473294/100/0/threaded"},{"name":"MS07-038","tags":["vendor-advisory","x_refsource_MS","x_transferred"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038"},{"name":"VU#101321","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/101321"},{"name":"1018354","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id?1018354"},{"name":"35952","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/35952"},{"name":"TA07-191A","tags":["third-party-advisory","x_refsource_CERT","x_transferred"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"26001","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26001"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-07-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka \"Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability.\""}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft"},"references":[{"name":"SSRT071446","tags":["vendor-advisory","x_refsource_HP"],"url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"win-vista-firewall-information-disclosure(35322)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35322"},{"name":"ADV-2007-2480","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/2480"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt"},{"name":"24779","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/24779"},{"name":"oval:org.mitre.oval:def:1884","tags":["vdb-entry","signature","x_refsource_OVAL"],"url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1884"},{"name":"20070709 SYMSA-2007-005: Vista Windows Firewall Incorrectly Applies Filtering to Teredo Interface","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/473294/100/0/threaded"},{"name":"MS07-038","tags":["vendor-advisory","x_refsource_MS"],"url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038"},{"name":"VU#101321","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/101321"},{"name":"1018354","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id?1018354"},{"name":"35952","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/35952"},{"name":"TA07-191A","tags":["third-party-advisory","x_refsource_CERT"],"url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"26001","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26001"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"secure@microsoft.com","ID":"CVE-2007-3038","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka \"Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability.\""}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"SSRT071446","refsource":"HP","url":"http://archive.cert.uni-stuttgart.de/bugtraq/2007/07/msg00254.html"},{"name":"win-vista-firewall-information-disclosure(35322)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/35322"},{"name":"ADV-2007-2480","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/2480"},{"name":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt","refsource":"CONFIRM","url":"http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-005.txt"},{"name":"24779","refsource":"BID","url":"http://www.securityfocus.com/bid/24779"},{"name":"oval:org.mitre.oval:def:1884","refsource":"OVAL","url":"https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1884"},{"name":"20070709 SYMSA-2007-005: Vista Windows Firewall Incorrectly Applies Filtering to Teredo Interface","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/473294/100/0/threaded"},{"name":"MS07-038","refsource":"MS","url":"https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-038"},{"name":"VU#101321","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/101321"},{"name":"1018354","refsource":"SECTRACK","url":"http://www.securitytracker.com/id?1018354"},{"name":"35952","refsource":"OSVDB","url":"http://osvdb.org/35952"},{"name":"TA07-191A","refsource":"CERT","url":"http://www.us-cert.gov/cas/techalerts/TA07-191A.html"},{"name":"26001","refsource":"SECUNIA","url":"http://secunia.com/advisories/26001"}]}}}},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2007-3038","datePublished":"2007-07-10T22:00:00.000Z","dateReserved":"2007-06-05T00:00:00.000Z","dateUpdated":"2024-08-07T13:57:54.941Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-07-10 22:30:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:N/A:N","baseScore":7.8,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:*:*:*:*:*:*:*","matchCriteriaId":"3852BB02-47A1-40B3-8E32-8D8891A53114"},{"vulnerable":true,"criteria":"cpe:2.3:o:microsoft:windows_vista:*:*:x64:*:*:*:*:*","matchCriteriaId":"1DD1D5ED-FE7C-4ADF-B3AF-1F13E51B4FB5"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"3038","Ordinal":"1","Title":"CVE-2007-3038","CVE":"CVE-2007-3038","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"3038","Ordinal":"1","NoteData":"The Teredo interface in Microsoft Windows Vista and Vista x64 Edition does not properly handle certain network traffic, which allows remote attackers to bypass firewall blocking rules and obtain sensitive information via crafted IPv6 traffic, aka \"Windows Vista Firewall Blocking Rule Information Disclosure Vulnerability.\"","Type":"Description","Title":"CVE-2007-3038"},{"CveYear":"2007","CveId":"3038","Ordinal":"2","NoteData":"2007-07-10","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"3038","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}