CVE-2007-2931
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 55.5%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 55.45% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20, CWE-119
- Affected
- microsoft/msn messenger · microsoft/windows live messenger
- Source
- cret@cert.org
References
- http://osvdb.org/40126
- http://secunia.com/advisories/26570Vendor Advisory
- http://www.kb.cert.org/vuls/id/166521US Government Resource
- http://www.securityfocus.com/bid/25461Exploit
- http://www.securitytracker.com/id?1018622
- http://www.team509.com/modules.php?name=News&file=article&sid=50Exploit
- http://www.us-cert.gov/cas/techalerts/TA07-254A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2987Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-054
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36314
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2063
- http://osvdb.org/40126
- http://secunia.com/advisories/26570Vendor Advisory
- http://www.kb.cert.org/vuls/id/166521US Government Resource
- http://www.securityfocus.com/bid/25461Exploit
- http://www.securitytracker.com/id?1018622
- http://www.team509.com/modules.php?name=News&file=article&sid=50Exploit
- http://www.us-cert.gov/cas/techalerts/TA07-254A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/2987Vendor Advisory
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-054
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36314
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2063
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.