Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invite request that contains hex-encoded spaces (%20) in the Invitation-Cookie field.
AV:N/AC:L/Au:N/C:N/I:N/A:P
This vulnerability has a 22.26% probability of being exploited in the next 30 days, ranking higher than 98% of all scored CVEs.