Vulnerability record · CVE-2007-0217 · published 13 February 2007
CVE-2007-0217: Internet Explorer wininet.dll FTP client heap corruption
Microsoft · Internet Explorer
The FTP client code in wininet.dll, used by Microsoft Internet Explorer 5.01 and 6, mishandles an FTP server response of a specific length, writing a terminating null byte outside an allocated buffer and corrupting the heap. Because the flaw is reachable from a remote FTP server and can lead to code execution, it is a serious client-side issue for the affected legacy browsers.
Description
The wininet.dll FTP client code in Microsoft Internet Explorer 5.01 and 6 might allow remote attackers to execute arbitrary code via an FTP server response of a specific length that causes a terminating null byte to be written outside of a buffer, which causes heap corruption.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityRemote, unauthenticated code execution with a 10.0 CVSS score and high EPSS, though limited to legacy IE versions and with no confirmed in-the-wild exploitation in this record.
What it is
The FTP client code in wininet.dll, used by Microsoft Internet Explorer 5.01 and 6, mishandles an FTP server response of a specific length, writing a terminating null byte outside an allocated buffer and corrupting the heap. Because the flaw is reachable from a remote FTP server and can lead to code execution, it is a serious client-side issue for the affected legacy browsers.
Impact
An attacker who controls or spoofs an FTP server can corrupt heap memory in the victim's browser process and potentially execute arbitrary code in the user's context.
Attack surface
Reached over the network when the browser processes a crafted FTP server response; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication is required, and exploitation depends on the victim connecting to the malicious FTP server, which may occur through normal browsing or a crafted link.
Exploitation
Not listed in CISA KEV and no reference tags indicate public exploit code, but EPSS is high (0.58363, 99th percentile), suggesting elevated likelihood of exploitation activity.
What to do
- Apply Microsoft security bulletin MS07-016, which addresses this vulnerability.
- Upgrade or migrate off Internet Explorer 5.01 and 6, which are no longer supported.
- Restrict outbound FTP traffic from browsers and endpoints where not operationally required.
- Block or proxy FTP access through a controlled gateway that filters malformed server responses.
Detection
- Monitor for iexplore.exe crashes or heap corruption events tied to FTP sessions.
- Alert on browser processes initiating outbound FTP connections to untrusted or newly seen servers.
- Review proxy and firewall logs for FTP traffic originating from Internet Explorer user agents.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-0217 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-0217), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.