CVE-2007-2931
published 2007-08-31CVE-2007-2931: Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code…
PriorityP356critical9.3CVSS 2.0
AVNACMAuNCCICAC
EXPLOIT
EPSS
55.45%
98.9th percentile
Heap-based buffer overflow in Microsoft MSN Messenger 6.2, 7.0, and 7.5, and Live Messenger 8.0 allows user-assisted remote attackers to execute arbitrary code via unspecified vectors involving video conversation handling in Web Cam and video chat sessions.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | msn_messenger | — | — |
| microsoft | msn_messenger | — | — |
| microsoft | msn_messenger | — | — |
| microsoft | windows_live_messenger | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit is delivered as a DLL injected into the MSN Messenger process; monitor for unexpected DLL injection into msnmsgr.exe. ↗
- →Exploitation is triggered during a webcam/video chat session ('send my webcam'); alert on heap-based buffer overflow conditions in MSN Messenger video conversation handling. ↗
- →Attacker may adjust a JMP address in the DLL source code for different Windows 2000 versions; look for modified/custom DLLs injected into MSN Messenger targeting specific OS offsets. ↗
- ·Exploit targets MSN Messenger version 7.0.777.0 specifically; other 7.x and 8.0 versions may require offset adjustments. ↗
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Exploit-DB
Microsoft MSN Messenger 7.x/8.0? - Video Remote Heap Overflow
exploitdb·2007-08-29
CVE-2007-2931 Microsoft MSN Messenger 7.x/8.0? - Video Remote Heap Overflow
Microsoft MSN Messenger 7.x/8.0? - Video Remote Heap Overflow
---
MSN messenger 7.x (8.0?) VIDEO Remote Heap Overflow Exploit
thanks ole andre again, His ospy is perfect.
1.compile the dll.
2.inject the dll to msn messenger 7.0.777.0 's process.
3. choose "send my webcam" to a contact id who is online using 7.x (8.0?).
4.when the otherside accept the invatation , the otherside's msn will be at least crashed, if you using aChinese version windows 2000 sp4 , maybe a reverse shell , if other verison windows 2000, you need adjust the jmpa address in the dll's sourcecode.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30537.rar (08292007-exp_msn.rar)
# milw0rm.com [2007-08-29]
Exploit-DB
Microsoft MSN Messenger 8.0 - Video Conversation Buffer Overflow
exploitdb·2007-08-28
CVE-2007-2931 Microsoft MSN Messenger 8.0 - Video Conversation Buffer Overflow
Microsoft MSN Messenger 8.0 - Video Conversation Buffer Overflow
---
source: https://www.securityfocus.com/bid/25461/info
Microsoft MSN Messenger is prone to a buffer-overflow vulnerability because it fails to perform adequate boundary checks on user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application. Failed exploit attempts will likely result in denial-of-service conditions.
https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/30537.rar
No writeups or analysis indexed.
http://osvdb.org/40126http://secunia.com/advisories/26570http://www.kb.cert.org/vuls/id/166521http://www.securityfocus.com/bid/25461http://www.securitytracker.com/id?1018622http://www.team509.com/modules.php?name=News&file=article&sid=50http://www.us-cert.gov/cas/techalerts/TA07-254A.htmlhttp://www.vupen.com/english/advisories/2007/2987https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-054https://exchange.xforce.ibmcloud.com/vulnerabilities/36314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2063http://osvdb.org/40126http://secunia.com/advisories/26570http://www.kb.cert.org/vuls/id/166521http://www.securityfocus.com/bid/25461http://www.securitytracker.com/id?1018622http://www.team509.com/modules.php?name=News&file=article&sid=50http://www.us-cert.gov/cas/techalerts/TA07-254A.htmlhttp://www.vupen.com/english/advisories/2007/2987https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-054https://exchange.xforce.ibmcloud.com/vulnerabilities/36314https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2063
2007-08-31
Published