CVE-2009-1491
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
05/05/2009
Last modified:
09/04/2025
Description
McAfee GroupShield for Microsoft Exchange on Exchange Server 2000, and possibly other anti-virus or anti-spam products from McAfee or other vendors, does not scan X- headers for malicious content, which allows remote attackers to bypass virus detection via a crafted message, as demonstrated by a message with an X-Testing header and no message body.
Impact
Base Score 2.0
9.30
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:mcafee:groupshield:*:*:*:*:*:*:*:* | ||
| cpe:2.3:a:microsoft:exchange_server:2000:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



