First published: Tue Oct 09 2007(Updated: )
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Outlook Express | <=6.0 | |
Microsoft Outlook Express | =6.0-sp1 | |
Microsoft Outlook.com |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-3897 is rated as critical due to its potential for remote code execution through a buffer overflow.
To fix CVE-2007-3897, users should upgrade to the latest version of Microsoft Outlook Express or Windows Mail that is no longer vulnerable.
CVE-2007-3897 specifically affects Microsoft Outlook Express 6.0 and earlier versions, as well as Windows Mail for Vista.
CVE-2007-3897 allows attackers to exploit heap-based buffer overflow vulnerabilities, leading to arbitrary code execution.
Yes, attackers can exploit CVE-2007-3897 by sending specially crafted NNTP responses to vulnerable email clients.