Dangerous vulnerability found in MSN Messenger
31st August 2007
A dangerous vulnerability has been detected in MSN Messenger, which is used by miscreants for gaining unauthorized access to a remote computer.
The bug was first reported by the author of the blog Zero Day. For organizing an attack through the bug, an attacker is to force a victims to participate in the session by video conference. If a user agrees to do so, the attacker may, by means of a specially formed data package, cause a heap overflow (heap-dynamic memory allocation). After that an arbitrary malicious code can be executed on the victim`s PC.
The vulnerability is present in the Internet pager MSN Messenger, versions 6. X and 7. X. There are no patches for this hole so far. The Danish company Secunia described the vulnerability as critically dangerous, and there are already examples in the internet of the code, which can use this hole.
Microsoft is already aware of the problem and is studying it. Users working with the abovementioned versions of MSN Messenger, are urged to switch to Windows Live Messenger 8.1.
It is quite interesting, that about two weeks ago, a similar vulnerability was identified in the internet pager Yahoo Messenger. However, developers of the Yahoo Messenger have already fixed their error.
Kantaris 0.2.0: alternative to Windows Media Player
Microsoft postpones release of Windows Server 2008Featured downloads
Interact
Now downloading
TextMaster
Open, validate, dedup, split horizontally and vertically, remove columns, reformat, check individual...
Open, validate, dedup, split horizontally and vertically, remove columns, reformat, check individual...
Blog categories
News blog











Download Free trial