PT-2005-2227 · Microsoft · Outlook Express

Published

2005-06-14

·

Updated

2018-10-12

·

CVE-2005-1213

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Outlook Express versions 5.5 SP2 through 6 SP1
Description A stack-based buffer overflow issue exists in the news reader component of Microsoft Outlook Express, allowing remote malicious NNTP servers to execute arbitrary code. This can be achieved by sending a LIST response with a long second field.
Recommendations For versions 5.5 SP2 through 6 SP1, consider disabling the news reader functionality until a patch is available. Restrict access to potentially malicious NNTP servers to minimize the risk of exploitation. Avoid using the affected news reader component in Microsoft Outlook Express until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1213

Affected Products

Outlook Express