Vulnerability record · CVE-2007-2931 · published 31 August 2007
CVE-2007-2931: Microsoft MSN/Live Messenger heap buffer overflow in video chat
Microsoft · Msn Messenger
A heap-based buffer overflow exists in Microsoft MSN Messenger 6.2, 7.0, 7.5 and Windows Live Messenger 8.0, triggered through unspecified vectors in Web Cam and video conversation handling. Because the flaw is memory corruption reachable over the network, successful exploitation can lead to arbitrary code execution on the victim's machine.
Description
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with a high CVSS score and public exploit references, though it requires user-assisted video interaction and affects only legacy Messenger clients.
What it is
A heap-based buffer overflow exists in Microsoft MSN Messenger 6.2, 7.0, 7.5 and Windows Live Messenger 8.0, triggered through unspecified vectors in Web Cam and video conversation handling. Because the flaw is memory corruption reachable over the network, successful exploitation can lead to arbitrary code execution on the victim's machine.
Impact
An attacker can execute arbitrary code with the privileges of the logged-in Messenger user, giving full control of confidentiality, integrity and availability on the affected host.
Attack surface
Reached remotely over the network through a Messenger video conversation; the CVSS vector (AV:N/AC:M/Au:N) indicates no authentication is required but some condition, consistent with the user-assisted nature of accepting or engaging in a video chat, must be met.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.55451, ~99th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Apply the Microsoft security update MS07-054 for the affected Messenger versions.
- Upgrade to a supported Messenger client that is not affected by this flaw.
- Block or restrict Messenger video/Web Cam traffic at the network perimeter where business use does not require it.
- Disable or remove the vulnerable Messenger clients on hosts that do not need them.
- Educate users not to accept video chat sessions from unknown contacts.
Detection
- Monitor for crashes or abnormal process termination in msnmsgr.exe or related Messenger processes during video sessions.
- Hunt for unexpected child processes or network connections spawned by Messenger after a video conversation.
- Review endpoint logs for memory-corruption indicators or exploit artifacts tied to Messenger video handling.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-2931 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-2931), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.