SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2007-3897

Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.

HIGH 9.3EPSS 54.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 54.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.

CVSS 2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
54.63% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-119
Affected
microsoft/outlook express · microsoft/windows mail
Source
secure@microsoft.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.