PT-2005-2227 · Microsoft · Outlook Express
Published
2005-06-14
·
Updated
2018-10-12
·
CVE-2005-1213
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Outlook Express versions 5.5 SP2 through 6 SP1
Description
A stack-based buffer overflow issue exists in the news reader component of Microsoft Outlook Express, allowing remote malicious NNTP servers to execute arbitrary code. This can be achieved by sending a LIST response with a long second field.
Recommendations
For versions 5.5 SP2 through 6 SP1, consider disabling the news reader functionality until a patch is available. Restrict access to potentially malicious NNTP servers to minimize the risk of exploitation. Avoid using the affected news reader component in Microsoft Outlook Express until the issue is resolved.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Outlook Express