Vulnerability record · CVE-2007-3897 · published 9 October 2007
CVE-2007-3897: Microsoft Outlook Express and Windows Mail NNTP heap buffer overflow
Microsoft · Outlook Express
Outlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server. A malicious or compromised news server can corrupt memory in the client, and the flaw carries a CVSS 2.0 score of 9.3, so it matters to any environment still running these mail/news clients.
Description
Heap-based buffer overflow in Microsoft Outlook Express 6 and earlier, and Windows Mail for Vista, allows remote Network News Transfer Protocol (NNTP) servers to execute arbitrary code via long NNTP responses that trigger memory corruption.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3 with a very high EPSS percentile indicates serious remote code execution risk, though no KEV listing or known exploit activity is recorded.
What it is
Outlook Express 6 and earlier, plus Windows Mail on Vista, contain a heap-based buffer overflow triggered by long responses from an NNTP news server. A malicious or compromised news server can corrupt memory in the client, and the flaw carries a CVSS 2.0 score of 9.3, so it matters to any environment still running these mail/news clients.
Impact
Successful exploitation allows the remote NNTP server to execute arbitrary code in the context of the client user, giving full compromise of confidentiality, integrity and availability per the CVSS vector.
Attack surface
Reached over the network via NNTP responses when a user connects to a news server; no authentication is required (Au:N), though the attack complexity is rated Medium and some user action, such as opening or reading a newsgroup, is implied by the client interaction.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.546 (99th percentile), and references are advisories and the MS07-056 patch with no public exploit tag.
What to do
- Apply Microsoft security bulletin MS07-056 (the vendor patch) to affected Outlook Express and Windows Mail installations.
- Retire or replace Outlook Express 6 and Windows Mail where possible, since these are legacy clients.
- Restrict or block outbound NNTP (TCP 119/563) traffic to trusted news servers only.
- Disable or remove unused news account configurations in mail clients.
- Segment and monitor hosts that must retain NNTP access.
Detection
- Monitor for client crashes or memory corruption events in msimn.exe or WinMail.exe after NNTP sessions.
- Alert on unexpected child processes spawned by Outlook Express or Windows Mail.
- Log and review NNTP connections to untrusted or newly seen servers.
- Hunt for unusual outbound NNTP traffic from endpoints that do not normally use newsgroups.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-3897 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-3897), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.