Exploitation Summary
EIP tracks 3 public exploits for CVE-2005-1213.
PoCs published by Metasploit, eyas, including Metasploit module exploits/windows/nntp/ms05_030_nntp.
AI-analyzed exploit summary This Metasploit module exploits a stack buffer overflow in Microsoft Outlook Express's NNTP response parsing. It sends a maliciously crafted response to trigger the vulnerability and execute arbitrary code via SEH overwrite.
Description
Stack-based buffer overflow in the news reader for Microsoft Outlook Express (MSOE.DLL) 5.5 SP2, 6, and 6 SP1 allows remote malicious NNTP servers to execute arbitrary code via a LIST response with a long second field.
Exploits (3)
This Metasploit module exploits a stack buffer overflow in Microsoft Outlook Express's NNTP response parsing. It sends a maliciously crafted response to trigger the vulnerability and execute arbitrary code via SEH overwrite.
This exploit targets a buffer overflow vulnerability in Microsoft Outlook Express (MS05-030) via the NNTP protocol. It sets up a malicious NNTP server on port 119 and sends a crafted response to trigger the overflow, executing shellcode for a bind shell on port 4444.
This Metasploit module exploits a stack buffer overflow in Microsoft Outlook Express's NNTP response parsing (CVE-2005-1213). It targets Windows 2000 and XP by sending a maliciously crafted NNTP response to trigger remote code execution.