You are here: silicon.com > Software > Security Strategy

Security Strategy

MSN Messenger flaw opens PCs up to hackers

Another Microsoft security hole...

By Graham Hayday

Published: 10 May 2002 09:30 GMT

Microsoft has admitted that a security flaw in its MSN Messenger software could allow hackers to delete files or cripple a user's computer.

The flaw enables hackers to exploit a feature that allows chat users in a single virtual location (i.e. a chat room) to exchange text messages in a separate ActiveX-based window.

Hackers can exploit the vulnerability to impose a buffer-overflow attack, according to Microsoft. Buffer-overflow vulnerabilities allow hackers to execute potentially harmful programs on a victim's computer, deleting files or crippling the system's security.

Attackers can issue the buffer overflow through HTML email or a malicious website.

MSN Chat Control, MSN Messenger versions 4.5 and 4.6, and Exchange Instant Messenger 4.5 and 4.6 are affected by the glitch.

The flaw was found by eEye Digital Security.

Users can download an updated version of MSN Messenger or Exchange Instant Messenger, or download an updated version of MSN Chat control from the company's chat websites.

See http://www.microsoft.com/technet for the security notice.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Nick Heath Your top HR tech priorities for next year revealed How to make human resources IT work for you

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business


  • Jobs
Net and XML Developer

Design and execute unit tests, ensuring they are executed successfully before releasing code to QA. Check all parameter files into source control. ...

Visual Files Developer / Visualfiles Development - Northwest

Visual Files Developer / Visualfiles Development - Northwest Salary: Good DOE Location: Northwest Position Type: Permanent Superb opportunity within ...

Project Manager - Telephony Implementation

The successful applicant will have implemented telephony solutions from Siemens or Cisco in the past as well as VoIP (including up to date add-ons), ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: