source: https://www.securityfocus.com/bid/668/info
There is a buffer overflow in the 4.71.0.10 version of the MSN Setup BBS ActiveX control (setupbbs.ocx).. This ActiveX control is marked 'Safe for Scripting' . Arbitrary commands may be executed if the ActiveX control is run in a malicious manner.
SETUPBBS:
When this control is initialised, it will display a prompt
notifying the user that the control is capable of modifying
Mail and News configuration etc and asks the user whether
he/she wishes the control to proceed. This control is
exploitable through two different methods, vAddNewsServer
and bIsNewsServerConfigured. I have simply RET'd to
ExitProcess with this exploit, although there are other
possibilities.