Vulnerability record · CVE-2005-1213 · published 14 June 2005
CVE-2005-1213: Microsoft Outlook Express news reader stack buffer overflow via NNTP LIST response
Microsoft · Outlook Express
The news reader component of Microsoft Outlook Express (MSOE.DLL) contains a stack-based buffer overflow triggered by a long second field in an NNTP LIST response. A remote malicious NNTP server can exploit this to run arbitrary code on the connecting client. The flaw affects Outlook Express 5.5 SP2, 6, and 6 SP1.
Description
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution with a very high EPSS score, though the product is legacy and no KEV listing or public exploit tag is present.
What it is
The news reader component of Microsoft Outlook Express (MSOE.DLL) contains a stack-based buffer overflow triggered by a long second field in an NNTP LIST response. A remote malicious NNTP server can exploit this to run arbitrary code on the connecting client. The flaw affects Outlook Express 5.5 SP2, 6, and 6 SP1.
Impact
An attacker who controls or compromises an NNTP server can execute arbitrary code in the context of the Outlook Express user. This gives full compromise of the client host without any user action beyond connecting to the malicious news server.
Attack surface
Reached over the network via NNTP; the victim must connect to a malicious or compromised news server, which can occur through normal newsgroup access. No authentication is required by the attacker, and no user interaction beyond the connection is needed.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.73961, 99.456th percentile), indicating elevated likelihood of exploitation activity. References include a vendor patch and advisory, but no public exploit tag is present in the record.
What to do
- Apply Microsoft security bulletin MS05-030 (the vendor patch) to affected Outlook Express versions.
- Disable or restrict Outlook Express news reader use where NNTP access is not required.
- Block outbound NNTP (TCP 119 and 563) to untrusted servers at the network perimeter.
- Upgrade to a supported mail/news client that is not affected by this legacy flaw.
- Limit user privileges so that any successful code execution has reduced impact.
Detection
- Monitor for Outlook Express (msimn.exe) crashes or abnormal process behavior when connecting to NNTP servers.
- Inspect network traffic for oversized or malformed NNTP LIST responses with unusually long second fields.
- Review endpoint logs for unexpected child processes spawned by Outlook Express after news server connections.
- Use the available OVAL definitions to scan for unpatched Outlook Express installations.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1213 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1213), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.