← Vulnerability feed

Vulnerability record · CVE-2007-3897 · published 9 October 2007

CVE-2007-3897: Microsoft Outlook Express and Windows Mail NNTP heap buffer overflow

Microsoft · Outlook Express

Outlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server. A malicious or compromised news server can corrupt memory in the client, and the flaw carries a CVSS 2.0 score of 9.3, so it matters to any environment still running these mail/news clients.

9.3 CVSS 2.0 High EPSS 55% · top 1.0% CWE-119 · Memory buffer overflow
9.3CVSS 2.0 base score
55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References
16 Jun 2026Last modified by NVD

Description

Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.

AV:N/AC:M/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityCVSS 9.3 with a very high EPSS percentile indicates serious remote code execution risk, though no KEV listing or known exploit activity is recorded.

What it is

Outlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server. A malicious or compromised news server can corrupt memory in the client, and the flaw carries a CVSS 2.0 score of 9.3, so it matters to any environment still running these mail/news clients.

Impact

Successful exploitation allows the remote NNTP server to execute arbitrary code in the context of the client user, giving full compromise of confidentiality, integrity and availability per the CVSS vector.

Attack surface

Reached over the network via NNTP responses when a user connects to a news server; no authentication is required (Au:N), though the attack complexity is rated Medium and some user action, such as opening or reading a newsgroup, is implied by the client interaction.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.546 (99th percentile), and references are advisories and the MS07-056 patch with no public exploit tag.

What to do

  • Apply Microsoft security bulletin MS07-056 (the vendor patch) to affected Outlook Express and Windows Mail installations.
  • Retire or replace Outlook Express 6 and Windows Mail where possible, since these are legacy clients.
  • Restrict or block outbound NNTP (TCP 119/563) traffic to trusted news servers only.
  • Disable or remove unused news account configurations in mail clients.
  • Segment and monitor hosts that must retain NNTP access.

Detection

  • Monitor for client crashes or memory corruption events in msimn.exe or WinMail.exe after NNTP sessions.
  • Alert on unexpected child processes spawned by Outlook Express or Windows Mail.
  • Log and review NNTP connections to untrusted or newly seen servers.
  • Hunt for unusual outbound NNTP traffic from endpoints that do not normally use newsgroups.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=607 Broken Link
http://secunia.com/advisories/27112 Third Party Advisory
http://securitytracker.com/id?1018785 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1018786 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/481983/100/100/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/482366/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/25908 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-282A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/3436 Permissions RequiredThird Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-056 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1706 Third Party Advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=607 Broken Link
http://secunia.com/advisories/27112 Third Party Advisory
http://securitytracker.com/id?1018785 Third Party AdvisoryVDB Entry
http://securitytracker.com/id?1018786 Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/481983/100/100/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/archive/1/482366/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/25908 Third Party AdvisoryVDB Entry
http://www.us-cert.gov/cas/techalerts/TA07-282A.html Third Party AdvisoryUS Government Resource
http://www.vupen.com/english/advisories/2007/3436 Permissions RequiredThird Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-056 PatchVendor Advisory
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1706 Third Party Advisory

Track CVE-2007-3897 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2004-0380Outlook Express MHTML handler domain bypass leads to code executionThe MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through 6 SP1 fails to enforce domain restrictions, letting remote attackers bypass s…EPSS 63%analysed10.0CVE-1999-0967Microsoft internet explorer vulnerabilityBuffer overflow in the HTML library used by Internet Explorer, Outlook Express, and Windows Explorer via the res: local resource protocol.EPSS 6.9%9.3CVE-2010-3147Microsoft outlook express vulnerabilityUntrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, W…EPSS 19%9.3CVE-2010-0816Microsoft outlook express vulnerabilityInteger overflow in inetcomm.dll in Microsoft Outlook Express 5.5 SP2, 6, and 6 SP1; Windows Live Mail on Windows XP SP2 and SP3, Windows Vista SP1 a…EPSS 20%8.8CVE-2007-4040Microsoft outlook cross-site scripting vulnerabilityArgument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduc…EPSS 13%8.8CVE-2003-1378Microsoft outlook permissions and access controls vulnerabilityMicrosoft Outlook Express 6.0 and Outlook 2000, with the security zone set to Internet Zone, allows remote attackers to execute arbitrary programs vi…EPSS 16%7.5CVE-2005-1213Microsoft Outlook Express news reader stack buffer overflow via NNTP LIST responseThe news reader component of Microsoft Outlook Express (MSOE.DLL) contains a stack-based buffer overflow triggered by a long second field in an NNTP …EPSS 74%analysed7.5CVE-2002-1179Microsoft outlook express vulnerabilityBuffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to execute arbitrary code via a dig…EPSS 22%

Source: NIST National Vulnerability Database (record CVE-2007-3897), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.