cbcvebase.
CVE-2007-2931
published 2007-08-31

CVE-2007-2931: Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code…

PriorityP356critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
55.45%
98.9th percentile
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.

Affected

4 ranges
VendorProductVersion rangeFixed in
microsoftmsn_messenger
microsoftmsn_messenger
microsoftmsn_messenger
microsoftwindows_live_messenger

Detection & IOCsextracted from sources · hover to see the quote

urlhttps://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30537.rar
  • Exploit is delivered as a DLL injected into the MSN Messenger process; monitor for unexpected DLL injection into msnmsgr.exe.
  • Exploitation is triggered during a webcam/video chat session ('send my webcam'); alert on heap-based buffer overflow conditions in MSN Messenger video conversation handling.
  • Attacker may adjust a JMP address in the DLL source code for different Windows 2000 versions; look for modified/custom DLLs injected into MSN Messenger targeting specific OS offsets.
  • ·Exploit targets MSN Messenger version 7.0.777.0 specifically; other 7.x and 8.0 versions may require offset adjustments.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.